The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login attempts depending on whether the username exists or corresponds to a privileged account, which allows remote attackers to enumerate account names and obtain sensitive information via a series of requests, aka Bug ID CSCuf28861.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2015-06-19T01:00:00
Updated: 2024-08-06T06:04:02.977Z
Reserved: 2015-06-04T00:00:00
Link: CVE-2015-4194
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2015-06-19T01:59:01.023
Modified: 2016-12-28T17:42:41.000
Link: CVE-2015-4194
Redhat
No data.