Improper Token Timer Implementation in Cisco WebEx Meetings Server 1.5 and Earlier

Improper Token Timer Implementation in Cisco WebEx Meetings Server 1.5 and Earlier

CVE-2014-3302 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:N

user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.

Learn more about our Cis Benchmark Audit For Cisco.