04-08-2014 12:25 PM - edited 03-17-2019 04:05 PM
Hello,
Following the recent alert for the HeartBleed vulnerability in OpenSSL I'm trying to determine if our WebEX meeting server v1.5 is vulnerable. I found the document below but it's not clear which particular version is in use - http://www.wbximg.com/includes/documents/Cisco_Webex_Meetings_Server_1.5_Open_Source_Documentation.pdf
Or, does this mean multiple version of OpenSSL are used??
Any help gratefully received!
04-09-2014 02:59 AM
I found that the CWMS 2.0.1.107.B-AE is exposed to vulnerability CVE-2014-0160 (OpenSSL HeartBleed)
04-09-2014 04:59 AM
Thanks for this - could you explain how you founds this info please? I'm hoping I can use the same method to find the info for CWMS1.5.
04-09-2014 11:57 AM
Hi BlueyVIII,
The Cisco PSIRT is investigating the impact of this vulnerability on Cisco products and will disclose any vulnerabilities according to our security policy, which is available at http://www.cisco.com/web/about/security/psirt/security_vulnerability_policy.html .
An INTERIM Cisco Security Advisory was published on April 9th, 2014 at 0300 UTC and is available at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-heartbleed
The Cisco PSIRT will update this Cisco Security Advisory as more information becomes available.
HTH
Atul
04-10-2014 08:15 PM
Hi BlueyVIII,
This vulnerability is seen only in CWMS 2.0 version and the previous versions are not affected by this vulnerability.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide