CVE-2013-3984
published 2014-05-26CVE-2013-3984: The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not set the secure flag for an unspecified cookie in an https session…
PriorityP49low2.9CVSS 2.0
AVAACMAuNCPINAN
EPSS
0.67%
48.1th percentile
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jj7f-gj82-922p: The Meeting Server in IBM Sametime 8
ghsa_unreviewed·2022-05-17·CVSS 2.9
CVE-2014-3867 [LOW] CWE-200 GHSA-jj7f-gj82-922p: The Meeting Server in IBM Sametime 8
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2013-3984.
GHSA
GHSA-26pr-grxv-7v6g: The Meeting Server in IBM Sametime 8
ghsa_unreviewed·2022-05-17
CVE-2013-3984 [LOW] CWE-200 GHSA-26pr-grxv-7v6g: The Meeting Server in IBM Sametime 8
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-05-26
Published