CVE-2014-3302

Cisco WebEx Meetings Server <= 1.5(.1.131) - Information Disclosure via user.php Token Timer

Title source: llm
STIX 2.1

Description

user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68904
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/94892
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58624
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030646

Scores

EPSS 0.0095
EPSS Percentile 57.6%

Details

CWE
CWE-310
Status published
Products (3)
cisco/webex_meetings_server 1.5
cisco/webex_meetings_server 1.5\(.1.6\)
cisco/webex_meetings_server < 1.5\(.1.131\)
Published Aug 01, 2014
Tracked Since Feb 18, 2026