SB2016091803 - Arbitrary command execution in Cisco WebEx Meetings Server



SB2016091803 - Arbitrary command execution in Cisco WebEx Meetings Server

Published: September 18, 2016 Updated: September 23, 2016

Security Bulletin ID SB2016091803
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Arbitrary command execution (CVE-ID: CVE-2016-1482)

The vulnerability exposes a remote user's possibility to cause arbitrary command execution on the target system.
The weakness exists due to improper input validation. By sending specially crafted data attackers can inject and execute arbitrary commands with elevated privileges.
Successful exploitation of the vulnerability may result in arbitrary command execution on the vulnerable system.

Remediation

Install update from vendor's website.