The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCuj40247.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/100662 | vdb entry |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8035 | vendor advisory |
http://www.securityfocus.com/bid/71980 | vdb entry |