Cisco Webex Meetings Server vulnerabilities

106 known vulnerabilities affecting cisco/webex_meetings_server.

Total CVEs
106
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH59MEDIUM38LOW1

Vulnerabilities

Page 5 of 6
CVE-2017-3797MEDIUMCVSS 5.3v2.7.1v2.7_base2017-01-26
CVE-2017-3797 [MEDIUM] CWE-200 CVE-2017-3797: A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to vi A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to view the fully qualified domain name of the Cisco WebEx administration server. More Information: CSCvb60655. Known Affected Releases: 2.7.
nvd
CVE-2016-1483HIGHCVSS 7.5v2.6.02016-09-19
CVE-2016-1483 [HIGH] CWE-20 CVE-2016-1483: Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumptio Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation component of an unspecified service, aka Bug ID CSCuy92704.
nvd
CVE-2016-1482HIGHCVSS 8.1v2.6.02016-09-17
CVE-2016-1482 [HIGH] CWE-78 CVE-2016-1482: Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting t Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into an application script, aka Bug ID CSCuy83130.
nvd
CVE-2016-1484HIGHCVSS 7.5v2.6.0v2.6.1.392016-08-23
CVE-2016-1484 [HIGH] CWE-20 CVE-2016-1484: Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and o Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspecified vectors, aka Bug ID CSCuy92724.
nvd
CVE-2016-1448HIGHCVSS 8.8v2.7.1v2.7_base2016-07-17
CVE-2016-1448 [HIGH] CWE-352 CVE-2016-1448: Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote att Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuy92706.
nvd
CVE-2016-1450HIGHCVSS 7.5v2.6.0v2.6.1.392016-07-15
CVE-2016-1450 [HIGH] CWE-20 CVE-2016-1450: Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attac Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attacks via vectors related to an upload's file type, aka Bug ID CSCuy92715.
nvd
CVE-2016-1446HIGHCVSS 8.8v2.6.0v2.6.1.392016-07-15
CVE-2016-1446 [HIGH] CWE-89 CVE-2016-1446: SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuy83200.
nvd
CVE-2016-1449MEDIUMCVSS 6.1v2.6.0v2.6.1.392016-07-15
CVE-2016-1449 [MEDIUM] CWE-79 CVE-2016-1449: Cross-site scripting (XSS) vulnerability in Cisco WebEx Meetings Server 2.6 allows remote attackers Cross-site scripting (XSS) vulnerability in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy92711.
nvd
CVE-2016-1447MEDIUMCVSS 6.1v2.6.0v2.6.1.392016-07-15
CVE-2016-1447 [MEDIUM] CWE-79 CVE-2016-1447: Cross-site scripting (XSS) vulnerability in the administrator interface in Cisco WebEx Meetings Serv Cross-site scripting (XSS) vulnerability in the administrator interface in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuy83194.
nvd
CVE-2016-1389HIGHCVSS 7.4v2.6.02016-04-28
CVE-2016-1389 [HIGH] CVE-2016-1389: Open redirect vulnerability in Cisco WebEx Meetings Server (CWMS) 2.6 allows remote attackers to red Open redirect vulnerability in Cisco WebEx Meetings Server (CWMS) 2.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCuy44695.
nvd
CVE-2016-1309MEDIUMCVSS 6.1v2.5.1.52016-02-07
CVE-2016-1309 [MEDIUM] CWE-79 CVE-2016-1309: Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meetings Server 2.5.1.5 allow rem Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meetings Server 2.5.1.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy01843.
nvd
CVE-2015-4281MEDIUMCVSS 6.8v2.5\(1\)2015-07-22
CVE-2015-4281 [MEDIUM] CWE-352 CVE-2015-4281: Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.5 MR1 allows remote Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.5 MR1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCus56150 and CSCus56146.
nvd
CVE-2015-4276MEDIUMCVSS 6.5v2.5\(1\)2015-07-16
CVE-2015-4276 [MEDIUM] CWE-20 CVE-2015-4276: Cisco WebEx Meetings Server 2.5MR1 allows remote authenticated users to execute arbitrary code via a Cisco WebEx Meetings Server 2.5MR1 allows remote authenticated users to execute arbitrary code via a crafted command parameter, aka Bug ID CSCus56138.
nvd
CVE-2015-0634MEDIUMCVSS 4.3v2.5v2.5.0.9972015-05-15
CVE-2015-0634 [MEDIUM] CWE-79 CVE-2015-0634: Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Ser Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Server 2.5 and 2.5.0.997 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuq86310.
nvd
CVE-2015-0668MEDIUMCVSS 4.3v2.5v2.5.99.22015-03-20
CVE-2015-0668 [MEDIUM] CWE-79 CVE-2015-0668: Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server 2.5 and 2.5.99.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuq66737.
nvd
CVE-2015-0589CRITICALCVSS 9.0v1.0v1.1+1 more2015-02-07
CVE-2015-0589 [CRITICAL] CWE-20 CVE-2015-0589: The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authen The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authenticated users to execute arbitrary OS commands with root privileges via unspecified fields, aka Bug ID CSCuj40460.
nvd
CVE-2015-0596MEDIUMCVSS 6.8≤ 1.5\(.1.131\)2015-02-02
CVE-2015-0596 [MEDIUM] CWE-352 CVE-2015-0596: Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 1.5(.1.131) and earli Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj67163.
nvd
CVE-2015-0597MEDIUMCVSS 5.0≤ 1.5\(.1.131\)2015-02-02
CVE-2015-0597 [MEDIUM] CWE-20 CVE-2015-0597: The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote att The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via crafted packets, aka Bug IDs CSCuj67166 and CSCuj67159.
nvd
CVE-2015-0595MEDIUMCVSS 5.0≤ 1.5\(.1.131\)2015-02-02
CVE-2015-0595 [MEDIUM] CWE-200 CVE-2015-0595: The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages from crafted GET requests, aka Bug ID CSCuj67079.
nvd
CVE-2014-8034MEDIUMCVSS 5.0v1.52015-01-15
CVE-2014-8034 [MEDIUM] CWE-255 CVE-2014-8034: Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which ma Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.
nvd