Improper input validation in Cisco WebEx Meeting Center - CVE-2017-12297
Published: December 1, 2017
Vulnerability details
The vulnerability allows a remote authenticated attacker to initiate connections to arbitrary hosts.
The vulnerability exists due to insufficient access control for HTTP traffic directed to the Cisco WebEx Meeting Center. A remote attacker can send a malicious URL to the Cisco WebEx Meeting Center and connect to arbitrary hosts.
Affected software
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
thunderbird (Red Hat package)