CVE-2016-1484
published 2016-08-23CVE-2016-1484: Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspecified…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.57%
72.6th percentile
Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspecified vectors, aka Bug ID CSCuy92724.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings_server | — | — |
| cisco | webex_meetings_server | — | — |
| cisco | webex_meetings_server | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco WebEx Meetings Server Information Disclosure Vulnerability
vendor_cisco·2016-08-17·CVSS 5.0
CVE-2016-1484 [MEDIUM] CWE-20 Cisco WebEx Meetings Server Information Disclosure Vulnerability
Cisco WebEx Meetings Server Information Disclosure Vulnerability
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data.
The vulnerability is due to lack of proper authentication controls. An attacker could exploit this vulnerability to learn sensitive information about the application.
Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-wms1
Cisco
Cisco WebEx Meetings Server Information Disclosure Vulnerability
vendor_cisco
CVE-2016-1484 Cisco WebEx Meetings Server Information Disclosure Vulnerability
CVE-2016-1484: Cisco WebEx Meetings Server Information Disclosure Vulnerability
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data. The vulnerability is due to lack of proper authentication controls. An attacker could exploit this vulnerability to learn sensitive information about the application. Cisco has released software updates that address this vulnerability.
CWE: CWE-20, CWE-20
Bug IDs: CSCuy92724
GHSA
GHSA-qfjj-g7h7-mc9h: Cisco WebEx Meetings Server 2
ghsa_unreviewed·2022-05-17
CVE-2016-1484 [HIGH] CWE-20 GHSA-qfjj-g7h7-mc9h: Cisco WebEx Meetings Server 2
Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspecified vectors, aka Bug ID CSCuy92724.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3097 spacewalk-java: Multiple XSS flaws
bugzilla·2016-03-31·CVSS 6.1
CVE-2016-3097 [MEDIUM] CVE-2016-3097 spacewalk-java: Multiple XSS flaws
CVE-2016-3097 spacewalk-java: Multiple XSS flaws
Group name is not properly escaped allowing XSS
An XSS vulnerability was found in WebUI when creating group with HTML via SSM or API and checking snapshot with this group join/leave.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1322710
Discussion:
Acknowledgments:
Name: Jan Hutař (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Satellite 5.7
Via RHSA-2016:1484 https://rhn.redhat.com/errata/RHSA-2016-1484.html
Bugzilla
CVE-2016-3080 spacewalk-monitoring: XSS issue in monitoring probe
bugzilla·2016-03-24·CVSS 6.1
CVE-2016-3080 [MEDIUM] CVE-2016-3080 spacewalk-monitoring: XSS issue in monitoring probe
CVE-2016-3080 spacewalk-monitoring: XSS issue in monitoring probe
XSS issue in monitoring probe was found.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1320461
Discussion:
Acknowledgments:
Name: Jan Hutař (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Satellite 5.7
Via RHSA-2016:1484 https://rhn.redhat.com/errata/RHSA-2016-1484.html
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-wms1http://www.securityfocus.com/bid/92519http://www.securitytracker.com/id/1036649http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-wms1http://www.securityfocus.com/bid/92519http://www.securitytracker.com/id/1036649
2016-08-23
Published