cbcvebase.

Cisco Webex Meetings Server vulnerabilities

106 known vulnerabilities affecting cisco/webex_meetings_server.

Total CVEs
106
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH59MEDIUM38LOW1

Vulnerabilities

Page 5 of 6
CVE-2014-3305P4MEDIUMCVSS 6.8≤ 1.5\(.1.131\)v1.5+1 more2014-07-26
CVE-2014-3305 [MEDIUM] CWE-352 CVE-2014-3305: Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuj81735.
nvd
CVE-2015-0596P4MEDIUMCVSS 6.8≤ 1.5\(.1.131\)2015-02-02
CVE-2015-0596 [MEDIUM] CWE-352 CVE-2015-0596: Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 1.5(.1.131) and earli Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj67163.
nvd
CVE-2017-12296P4MEDIUMCVSS 6.1v2.6v2.7+1 more2017-10-19
CVE-2017-12296 [MEDIUM] CWE-79 CVE-2017-12296: A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to co A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulne
nvd
CVE-2021-1525P4MEDIUMCVSS 6.1fixed in 3.0v3.0+1 more2021-06-04
CVE-2021-1525 [MEDIUM] CWE-601 CVE-2021-1525: A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticat A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malicious file. This vulnerability is due to improper validation of URL paths in the application interface. An attacker could exploit this vulnerability by persuading a user to follow a specially crafted URL th
nvd
CVE-2015-4281P4MEDIUMCVSS 6.8v2.5\(1\)2015-07-22
CVE-2015-4281 [MEDIUM] CWE-352 CVE-2015-4281: Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.5 MR1 allows remote Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.5 MR1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCus56150 and CSCus56146.
nvd
CVE-2019-1954P4MEDIUMCVSS 6.1fixed in 4.0\(1\)2019-08-08
CVE-2019-1954 [MEDIUM] CWE-601 CVE-2019-1954: A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected device. An attacker could exploit this vulne
nvd
CVE-2019-1655P4MEDIUMCVSS 6.1v2.82019-01-24
CVE-2019-1655 [MEDIUM] CWE-79 CVE-2019-1655: A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An att
nvd
CVE-2014-2199P4MEDIUMCVSS 5.0≤ 1.5\(.1.131\)2014-05-20
CVE-2014-2199 [MEDIUM] CWE-200 CVE-2014-2199: meetinginfo.do in Cisco WebEx Event Center, WebEx Meeting Center, WebEx Sales Center, WebEx Training meetinginfo.do in Cisco WebEx Event Center, WebEx Meeting Center, WebEx Sales Center, WebEx Training Center, WebEx Meetings Server 1.5(.1.131) and earlier, and WebEx Business Suite (WBS) 27 before 27.32.31.16, 28 before 28.12.13.18, and 29 before 29.5.1.12 allows remote attackers to obtain sensitive meeting information by leveraging knowledge of a mee
nvd
CVE-2021-1372P4MEDIUMCVSS 5.5fixed in 4.0v4.02021-02-17
CVE-2021-1372 [MEDIUM] CWE-202 CVE-2021-1372: A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could a A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. This vulnerability is due to the unsafe usage of shared memory by the affected software. An attacker with permissions to view system memory could exploi
nvd
CVE-2016-1447P4MEDIUMCVSS 6.1v2.6.0v2.6.1.392016-07-15
CVE-2016-1447 [MEDIUM] CWE-79 CVE-2016-1447: Cross-site scripting (XSS) vulnerability in the administrator interface in Cisco WebEx Meetings Serv Cross-site scripting (XSS) vulnerability in the administrator interface in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuy83194.
nvd
CVE-2016-1449P4MEDIUMCVSS 6.1v2.6.0v2.6.1.392016-07-15
CVE-2016-1449 [MEDIUM] CWE-79 CVE-2016-1449: Cross-site scripting (XSS) vulnerability in Cisco WebEx Meetings Server 2.6 allows remote attackers Cross-site scripting (XSS) vulnerability in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy92711.
nvd
CVE-2014-3302P4MEDIUMCVSS 5.8≤ 1.5\(.1.131\)v1.5+1 more2014-08-01
CVE-2014-3302 [MEDIUM] CWE-310 CVE-2014-3302: user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the toke user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.
nvd
CVE-2015-0595P4MEDIUMCVSS 5.0≤ 1.5\(.1.131\)2015-02-02
CVE-2015-0595 [MEDIUM] CWE-200 CVE-2015-0595: The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages from crafted GET requests, aka Bug ID CSCuj67079.
nvd
CVE-2014-3301P4MEDIUMCVSS 5.0≤ 1.5\(.1.131\)v1.5+1 more2014-07-26
CVE-2014-3301 [MEDIUM] CWE-200 CVE-2014-3301: The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows re The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned messages, aka Bug ID CSCuj81700.
nvd
CVE-2016-1309P4MEDIUMCVSS 6.1v2.5.1.52016-02-07
CVE-2016-1309 [MEDIUM] CWE-79 CVE-2016-1309: Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meetings Server 2.5.1.5 allow rem Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meetings Server 2.5.1.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy01843.
nvd
CVE-2014-8034P4MEDIUMCVSS 5.0v1.52015-01-15
CVE-2014-8034 [MEDIUM] CWE-255 CVE-2014-8034: Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which ma Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.
nvd
CVE-2021-1517P4MEDIUMCVSS 4.3fixed in 3.0v3.0+1 more2021-06-04
CVE-2021-1517 [MEDIUM] CWE-693 CVE-2021-1517: A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Se A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the multimedia viewer feature. An attacker could exploit this vulnerability by sharing a file throug
nvd
CVE-2015-0634P4MEDIUMCVSS 4.3v2.5v2.5.0.9972015-05-15
CVE-2015-0634 [MEDIUM] CWE-79 CVE-2015-0634: Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Ser Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Server 2.5 and 2.5.0.997 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuq86310.
nvd
CVE-2020-3345P4MEDIUMCVSS 4.3≤ 4.0v4.02020-07-16
CVE-2020-3345 [MEDIUM] CWE-20 CVE-2020-3345: A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could a A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to modify a web page in the context of a browser. The vulnerability is due to improper checks on parameter values within affected pages. An attacker could exploit this vulnerability by persuading a user to follow
nvd
CVE-2021-1221P4MEDIUMCVSS 4.1fixed in 3.0v3.0+1 more2021-02-04
CVE-2021-1221 [MEDIUM] CWE-20 CVE-2021-1221: A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Softwa A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Software could allow an authenticated, remote attacker to inject a hyperlink into a meeting invitation email. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by entering a URL into a field in the user int
nvd
Cisco Webex Meetings Server vulnerabilities | cvebase