Release date:
Updated on:
Affected Systems:
Cisco WebEx Meetings Server
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64980
CVE (CAN) ID: CVE-2013-6687
Cisco WebEx Meetings is a network conferencing solution.
The Server password is saved in the source code of the web page of the Cisco WebEx Meetings Server Enterprise License Manager. The implementation of the password leakage vulnerability exists, authenticated remote attackers can view the plaintext administrator password of the Cisco WebEx Meetings Server.
<* Source: vendor
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6687%E9%98%BF
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (CVE-2013-6687) and patches for this:
CVE-2013-6687: Cisco WebEx Meetings Server Enterprise License Manager Administrative Password Disclosure Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6687%E9%98%BF