5

CVE-2014-2199

meetinginfo.do in Cisco WebEx Event Center, WebEx Meeting Center, WebEx Sales Center, WebEx Training Center, WebEx Meetings Server 1.5(.1.131) and earlier, and WebEx Business Suite (WBS) 27 before 27.32.31.16, 28 before 28.12.13.18, and 29 before 29.5.1.12 allows remote attackers to obtain sensitive meeting information by leveraging knowledge of a meeting identifier, aka Bug IDs CSCuo68624 and CSCue46738.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Webex Business Suite Version 27.0
Cisco ≫ Webex Business Suite Version 28.0
Cisco ≫ Webex Business Suite Version 29.0
Cisco ≫ Webex Event Center Version -
Cisco ≫ Webex Meeting Center Version -
Cisco ≫ Webex Meetings Server Version <= 1.5\(.1.131\)
Cisco ≫ Webex Sales Center Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.65% 0.735
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2199
Vendor Advisory
http://tools.cisco.com/security/center/viewAlert.x?alertId=34252
Vendor Advisory
http://www.securitytracker.com/id/1030251
Third Party Advisory
VDB Entry