cbcvebase.

Ibm Sametime vulnerabilities

46 known vulnerabilities affecting ibm/sametime.

Total CVEs
46
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM34LOW9

Vulnerabilities

Page 1 of 3
CVE-2013-3982P3MEDIUMCVSS 5.0PoCv8.0.0.0v8.0.1.0+10 more2014-05-26
CVE-2013-3982 [MEDIUM] CWE-200 CVE-2013-3982: The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attacke The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspecified installation information and technical data via a request to a public page.
nvd
CVE-2013-3975P3MEDIUMCVSS 5.0PoCv8.0.0.0v8.0.1.0+10 more2014-05-26
CVE-2013-3975 [MEDIUM] CVE-2013-3975: Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to discover user names, full names, and e-mail addresses via a search.
nvd
CVE-2013-3977P3MEDIUMCVSS 4.3PoCv8.0.0.0v8.0.1.0+10 more2014-05-26
CVE-2013-3977 [MEDIUM] CWE-287 CVE-2013-3977: The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attacke The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge of valid user names.
nvd
CVE-2013-6742P3HIGHCVSS 7.5v8.5.2.0v8.5.2.1+2 more2014-02-14
CVE-2013-6742 [HIGH] CWE-264 CVE-2013-6742: The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
nvd
CVE-2016-2972P3HIGHCVSS 7.8v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2972 [HIGH] CWE-255 CVE-2016-2972: IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in t IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855.
nvd
CVE-2016-0355P4MEDIUMCVSS 6.5v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-0355 [MEDIUM] CWE-352 CVE-2016-0355: IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111894.
nvd
CVE-2016-0356P4MEDIUMCVSS 6.5v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-0356 [MEDIUM] CWE-352 CVE-2016-0356: IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111895.
nvd
CVE-2013-3983P4HIGHCVSS 7.5v8.5.2.0v8.5.2.1+2 more2014-02-14
CVE-2013-3983 [HIGH] CWE-20 CVE-2013-3983: The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate U The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redirects, which has unspecified impact and remote attack vectors.
nvd
CVE-2013-3988P4MEDIUMCVSS 6.8v8.5.2.0v8.5.2.1+2 more2014-02-14
CVE-2013-3988 [MEDIUM] CWE-20 CVE-2013-3988: The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attac The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
nvd
CVE-2013-3981P4MEDIUMCVSS 5.0v8.0.0.0v8.0.1.0+10 more2014-05-26
CVE-2013-3981 [MEDIUM] CWE-264 CVE-2013-3981: The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attacke The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to download avatar photos of arbitrary users via unspecified vectors.
nvd
CVE-2012-3331P4MEDIUMCVSS 5.3v6.5.1.0v7.0.0.0+13 more2018-02-08
CVE-2012-3331 [MEDIUM] CWE-200 CVE-2012-3331: IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID: 78048.
nvd
CVE-2016-0354P4MEDIUMCVSS 5.5v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-0354 [MEDIUM] CWE-434 CVE-2016-0354: IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a m IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893.
nvd
CVE-2016-2965P4MEDIUMCVSS 6.5v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2965 [MEDIUM] CWE-352 CVE-2016-2965: IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by imp IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious link, a remote attacker could force the user to log out of Sametime. IBM X-Force ID: 113846.
nvd
CVE-2016-2980P4MEDIUMCVSS 6.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2980 [MEDIUM] CWE-74 CVE-2016-2980: The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Force ID: 113993.
nvd
CVE-2016-2971P4MEDIUMCVSS 5.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2971 [MEDIUM] CWE-200 CVE-2016-2971: IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error lo IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. IBM X-Force ID: 113898.
nvd
CVE-2016-2979P4MEDIUMCVSS 5.4v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2979 [MEDIUM] CWE-79 CVE-2016-2979: IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113945.
nvd
CVE-2016-2973P4MEDIUMCVSS 5.4v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2973 [MEDIUM] CWE-79 CVE-2016-2973: IBM Sametime Media Services 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability IBM Sametime Media Services 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113899.
nvd
CVE-2016-2975P4MEDIUMCVSS 5.4v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2975 [MEDIUM] CWE-79 CVE-2016-2975: IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113935.
nvd
CVE-2013-6727P4MEDIUMCVSS 5.0v8.5.2.0v8.5.2.1+1 more2014-01-31
CVE-2013-6727 [MEDIUM] CWE-264 CVE-2013-6727: The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restri The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-3867P4MEDIUMCVSS 5.0v8.0.0.0v8.0.1.0+10 more2014-05-26
CVE-2014-3867 [MEDIUM] CVE-2014-3867: The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2013-3984.
nvd
Ibm Sametime vulnerabilities | cvebase