VulnerabilityModified
CVE-2014-3296
The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.
MEDIUM 4.0EPSS 1.30%
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- cisco/webex meetings server
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/59263
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3296Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=34663Vendor Advisory
- http://www.securityfocus.com/bid/68118Third Party Advisory, VDB Entry
- http://secunia.com/advisories/59263
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3296Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=34663Vendor Advisory
- http://www.securityfocus.com/bid/68118Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.