ID

VAR-201407-0368


CVE

CVE-2014-3304


TITLE

Cisco WebEx Meetings Server of OutlookAction User account enumeration vulnerability in class

Trust: 0.8

sources: JVNDB: JVNDB-2014-003608

DESCRIPTION

The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering crafted URLs and examining the returned messages, aka Bug ID CSCuj81722. Cisco WebEx Meetings is a networked online conferencing product in Cisco's WebEx conferencing solution. An attacker can leverage this issue to obtain sensitive information like valid user accounts, that may aid in further attacks. This issue is being tracked by Cisco bug ID CSCuj81722. There is a security hole in the OutlookAction Class of CWMS, which is caused by the program not filtering the return message correctly

Trust: 2.52

sources: NVD: CVE-2014-3304 // JVNDB: JVNDB-2014-003608 // CNVD: CNVD-2014-04674 // BID: 68911 // VULHUB: VHN-71244

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-04674

AFFECTED PRODUCTS

vendor:ciscomodel:webex meetings serverscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:webex meetings serverscope:lteversion:1.5(.1.131)

Trust: 0.8

vendor:ciscomodel:webex meetings serverscope: - version: -

Trust: 0.6

vendor:ciscomodel:webex meetings serverscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2014-04674 // BID: 68911 // JVNDB: JVNDB-2014-003608 // CNNVD: CNNVD-201407-663 // NVD: CVE-2014-3304

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-3304
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-3304
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-04674
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201407-663
value: MEDIUM

Trust: 0.6

VULHUB: VHN-71244
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-3304
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-04674
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-71244
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-04674 // VULHUB: VHN-71244 // JVNDB: JVNDB-2014-003608 // CNNVD: CNNVD-201407-663 // NVD: CVE-2014-3304

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-71244 // JVNDB: JVNDB-2014-003608 // NVD: CVE-2014-3304

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201407-663

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201407-663

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-003608

PATCH

title:Cisco WebEx Meetings Server OutlookAction Class Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3304

Trust: 0.8

title:35060url:http://tools.cisco.com/security/center/viewAlert.x?alertId=35060

Trust: 0.8

sources: JVNDB: JVNDB-2014-003608

EXTERNAL IDS

db:NVDid:CVE-2014-3304

Trust: 3.4

db:BIDid:68911

Trust: 2.0

db:SECTRACKid:1030641

Trust: 1.1

db:JVNDBid:JVNDB-2014-003608

Trust: 0.8

db:CNNVDid:CNNVD-201407-663

Trust: 0.7

db:CNVDid:CNVD-2014-04674

Trust: 0.6

db:VULHUBid:VHN-71244

Trust: 0.1

sources: CNVD: CNVD-2014-04674 // VULHUB: VHN-71244 // BID: 68911 // JVNDB: JVNDB-2014-003608 // CNNVD: CNNVD-201407-663 // NVD: CVE-2014-3304

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-3304

Trust: 2.0

url:http://www.securityfocus.com/bid/68911

Trust: 1.7

url:http://www.securitytracker.com/id/1030641

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/94880

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-3304

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-3304

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2014-04674 // VULHUB: VHN-71244 // BID: 68911 // JVNDB: JVNDB-2014-003608 // CNNVD: CNNVD-201407-663 // NVD: CVE-2014-3304

CREDITS

Cisco

Trust: 0.3

sources: BID: 68911

SOURCES

db:CNVDid:CNVD-2014-04674
db:VULHUBid:VHN-71244
db:BIDid:68911
db:JVNDBid:JVNDB-2014-003608
db:CNNVDid:CNNVD-201407-663
db:NVDid:CVE-2014-3304

LAST UPDATE DATE

2024-11-23T22:39:00.508000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-04674date:2014-07-30T00:00:00
db:VULHUBid:VHN-71244date:2017-08-29T00:00:00
db:BIDid:68911date:2014-07-25T00:00:00
db:JVNDBid:JVNDB-2014-003608date:2014-07-30T00:00:00
db:CNNVDid:CNNVD-201407-663date:2014-07-29T00:00:00
db:NVDid:CVE-2014-3304date:2024-11-21T02:07:49.760

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-04674date:2014-07-30T00:00:00
db:VULHUBid:VHN-71244date:2014-07-28T00:00:00
db:BIDid:68911date:2014-07-25T00:00:00
db:JVNDBid:JVNDB-2014-003608date:2014-07-30T00:00:00
db:CNNVDid:CNNVD-201407-663date:2014-07-29T00:00:00
db:NVDid:CVE-2014-3304date:2014-07-28T17:55:07.293