CVE-2013-3975
published 2014-05-26CVE-2013-3975: Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to discover user names…
PriorityP335medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
13.15%
95.9th percentile
Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to discover user names, full names, and e-mail addresses via a search.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is exploitable via the IBM Sametime Meeting Server web interface — monitor for abnormal or automated search/enumeration requests against the Sametime web interface, particularly dictionary-based or brute-force username lookups. ↗
- →The attack targets IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 Meeting Server; detection should focus on these specific version ranges. ↗
- ·The vulnerability is described as 'unspecified' by the vendor — no specific endpoint, parameter, or request format is publicly documented, limiting precise signature-based detection. ↗
- ·The Metasploit module supports both dictionary and brute-force attack modes; a dictionary attack is noted as preferred, meaning detection rules should account for both high-volume sequential requests (brute-force) and lower-volume but targeted requests (dictionary). ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
2014-05-26
Published