Impact
A vulnerable version of the Cisco Webex app for Splunk SOAR discloses sensitive meeting passwords through the schedule meeting action. The action parameter that holds the password is not marked as a password, so it is rendered in cleartext in the Splunk SOAR user interface for any user who has permission to run actions. This satisfies CWE‑312, Sensitive Data Exposure, and could reveal credentials used for Webex meetings to the viewing user.
Affected Systems
The issue affects the Cisco Webex app for Splunk SOAR in all releases prior to 2.2.1. The fixed app requires Splunk SOAR version 8.6.0 or higher. The product is published by Splunk under the name Cisco Webex app for Splunk SOAR.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting the exploitation probability is not well documented. Exploitation requires a user with the ability to execute actions within Splunk SOAR, which is typically an internal role, so the attack vector is likely limited to authenticated internal users.
OpenCVE Enrichment