CVE-2016-2979
published 2017-08-29CVE-2016-2979: IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…
PriorityP424medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.75%
50.9th percentile
IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113945.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6v8-836h-83f7: IBM Sametime Meeting Server 8
ghsa_unreviewed·2022-05-17
CVE-2016-2979 [MEDIUM] CWE-79 GHSA-f6v8-836h-83f7: IBM Sametime Meeting Server 8
IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113945.
OSV
linux-lts-xenial vulnerabilities
osv·2016-05-16·CVSS 7.8
linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-2979-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
David Matlack discovered that the Kernel-based Virtual Machine (KVM)
implementation in the Linux kernel did not properly restrict variable
Memory Type Range Registers (MTRR) in KVM guests. A privileged user in a
guest VM could use this to cause a denial of service (system crash) in the
host, expose sensitive information from the host, or possibly gain
administrative privileges in the host. (CVE-2016-3713)
Philip Pettersson discovered that the Linux kernel's ASN.1 DER decoder did
not properly process certificate files with tags of indefinite leng
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.ibm.com/support/docview.wss?uid=swg22006439http://www.securityfocus.com/bid/100599http://www.securitytracker.com/id/1039231https://exchange.xforce.ibmcloud.com/vulnerabilities/113945http://www.ibm.com/support/docview.wss?uid=swg22006439http://www.securityfocus.com/bid/100599http://www.securitytracker.com/id/1039231https://exchange.xforce.ibmcloud.com/vulnerabilities/113945
2017-08-29
Published