Information disclosure in Cisco WebEx Meetings Server - CVE-2017-12295
Published: November 2, 2017
Vulnerability identifier: #VU9099
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-12295
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Cisco WebEx Meetings Server
Cisco WebEx Meetings Server
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists in Cisco WebEx Meetings Server due to the HTTP header reply from the Cisco WebEx Meetings Server to the client, which could include internal network information that should be restricted. A remote attacker can attempt to use the HTTP protocol, access the data in the HTTP responses from the Cisco WebEx Meetings Server and discover sensitive data about the application.
The weakness exists in Cisco WebEx Meetings Server due to the HTTP header reply from the Cisco WebEx Meetings Server to the client, which could include internal network information that should be restricted. A remote attacker can attempt to use the HTTP protocol, access the data in the HTTP responses from the Cisco WebEx Meetings Server and discover sensitive data about the application.
How to mitigate CVE-2017-12295
Update to version 2.8.1.1019 or 2.8.1.1023.