Vulnerability Name:

CVE-2014-2199 (CCN-93172)

Assigned:2014-05-15
Published:2014-05-15
Updated:2016-09-07
Summary:meetinginfo.do in Cisco WebEx Event Center, WebEx Meeting Center, WebEx Sales Center, WebEx Training Center, WebEx Meetings Server 1.5(.1.131) and earlier, and WebEx Business Suite (WBS) 27 before 27.32.31.16, 28 before 28.12.13.18, and 29 before 29.5.1.12 allows remote attackers to obtain sensitive meeting information by leveraging knowledge of a meeting identifier, aka Bug IDs CSCuo68624 and CSCue46738.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2014-2199

Source: CCN
Type: Cisco Security Notice
WebEx Meeting Information Disclosure Vulnerability in meetinginfo.do

Source: CISCO
Type: Vendor Advisory
20140515 WebEx Meeting Information Disclosure Vulnerability in meetinginfo.do

Source: CONFIRM
Type: Vendor Advisory
http://tools.cisco.com/security/center/viewAlert.x?alertId=34252

Source: CCN
Type: BID-67424
Cisco WebEx Business Suite 'meetinginfo.do' Information Disclosure Vulnerability

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1030251

Source: XF
Type: UNKNOWN
cisco-webex-cve20142199-info-disc(93172)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:cisco:webex_business_suite:27.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:webex_business_suite:28.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:webex_business_suite:29.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:webex_event_center:-:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:webex_meeting_center:-:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:webex_meetings_server:*:*:*:*:*:*:*:* (Version <= 1.5(.1.131))
  • OR cpe:/a:cisco:webex_sales_center:-:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:webex_training_center:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    cisco webex business suite 27.0
    cisco webex business suite 28.0
    cisco webex business suite 29.0
    cisco webex event center -
    cisco webex meeting center -
    cisco webex meetings server *
    cisco webex sales center -
    cisco webex training center -