Executive brief
Cisco WebEx Meetings Server is a private cloud solution for hosting online meetings and collaboration. A vulnerability in this server could allow an unauthorized person to see the internal web address (domain name) of the administration server. While this does not grant direct access to meeting data, it provides an attacker with technical details about the internal network structure that could be used to plan further attacks.
Technical details
An information disclosure vulnerability (CWE-200) exists in Cisco WebEx Meetings Server due to insufficient masking of sensitive data in HTTP responses. A remote, unauthenticated attacker can exploit this by sending specific HTTP requests to the affected system. Successful exploitation allows the attacker to retrieve the fully qualified domain name (FQDN) of the administration server. This vulnerability affects version 2.7; Cisco has released software updates to address the issue, and no workarounds are available.
Affected products
- Cisco WebEx Meetings Server 2.7
Timeline
- 2017-01-18: advisory: Initial Cisco advisory release
- 2017-01-26: disclosed: NVD publication date