cbcvebase.

Ibm Sametime vulnerabilities

46 known vulnerabilities affecting ibm/sametime.

Total CVEs
46
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM34LOW9

Vulnerabilities

Page 2 of 3
CVE-2016-2964P4MEDIUMCVSS 5.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2964 [MEDIUM] CWE-200 CVE-2016-2964: IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too detailed and may reveal details about the application. IBM X-Force ID: 113813.
nvd
CVE-2016-2967P4MEDIUMCVSS 5.4v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2967 [MEDIUM] CWE-79 CVE-2016-2967: IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Sametime away message altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113848.
nvd
CVE-2013-3980P4MEDIUMCVSS 5.0v8.0.0.0v8.0.1.0+10 more2014-05-26
CVE-2013-3980 [MEDIUM] CWE-20 CVE-2013-3980: The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attacke The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to cause a denial of service (room unusability) by generating a large number of fictitious users to enter a meeting room.
nvd
CVE-2016-2959P4MEDIUMCVSS 4.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2959 [MEDIUM] CWE-264 CVE-2016-2959: IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary m IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges. IBM X-Force ID: 113804.
nvd
CVE-2016-2966P4MEDIUMCVSS 4.3v8.5.1.0v8.5.1.1+7 more2017-08-29
CVE-2016-2966 [MEDIUM] CWE-200 CVE-2016-2966: IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing the meeting room id. IBM X-Force ID: 113847.
nvd
CVE-2013-3978P4MEDIUMCVSS 5.0v8.5.2.0v8.5.2.1+2 more2014-02-14
CVE-2013-3978 [MEDIUM] CWE-264 CVE-2013-3978: The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the a The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwanted caching by a web browser, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
nvd
CVE-2014-4748P4MEDIUMCVSS 4.3v8.0.0.0v8.0.1.0+8 more2014-07-26
CVE-2014-4748 [MEDIUM] CWE-79 CVE-2014-4748: Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8 Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2012-3308P4MEDIUMCVSS 4.3v8.0.2.0v8.0.2.1+5 more2012-08-17
CVE-2012-3308 [MEDIUM] CWE-79 CVE-2012-3308: Cross-site scripting (XSS) vulnerability in IBM Sametime 8.0.2 through 8.5.2.1 allows remote attacke Cross-site scripting (XSS) vulnerability in IBM Sametime 8.0.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via an IM chat.
nvd
CVE-2014-0906P4MEDIUMCVSS 4.3v8.0.0.0v8.0.1.0+9 more2014-05-26
CVE-2014-0906 [MEDIUM] CWE-264 CVE-2014-0906: The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not check whethe The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not check whether a session cookie is current, which allows remote attackers to conduct user-search actions by leveraging possession of a (1) expired or (2) invalidated cookie.
nvd
CVE-2016-0358P4MEDIUMCVSS 4.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-0358 [MEDIUM] CWE-200 CVE-2016-0358: IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928.
nvd
CVE-2016-2976P4MEDIUMCVSS 4.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2976 [MEDIUM] CWE-200 CVE-2016-2976: IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared sensitive information by viewing the meeting report history. IBM X-Force ID: 113936.
nvd
CVE-2016-2977P4MEDIUMCVSS 4.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2977 [MEDIUM] CWE-20 CVE-2016-2977: IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in the meeting. IBM X-Force ID: 113937.
nvd
CVE-2016-10503P4MEDIUMCVSS 4.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-10503 [MEDIUM] CWE-20 CVE-2016-10503: IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. IBM X-Force ID: 113803.
nvd
CVE-2013-6733P4MEDIUMCVSS 4.3v7.5.1.2v8.0.0.0+9 more2013-12-17
CVE-2013-6733 [MEDIUM] CWE-79 CVE-2013-6733: Cross-site scripting (XSS) vulnerability in the Web Application in the Classic Meeting Server in IBM Cross-site scripting (XSS) vulnerability in the Web Application in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2016-2969P4MEDIUMCVSS 4.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2969 [MEDIUM] CWE-200 CVE-2016-2969: IBM Sametime Meeting Server 8.5.2 and 9.0 may send replies that contain emails of people that should IBM Sametime Meeting Server 8.5.2 and 9.0 may send replies that contain emails of people that should not be in these messages. IBM X-Force ID: 113850.
nvd
CVE-2016-2970P4MEDIUMCVSS 4.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2970 [MEDIUM] CWE-200 CVE-2016-2970: IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that m IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers. IBM X-Force ID: 113851.
nvd
CVE-2013-3046P4MEDIUMCVSS 4.3v8.0.0.0v8.0.1.0+10 more2014-05-26
CVE-2013-3046 [MEDIUM] CWE-287 CVE-2013-3046: The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not send the HST The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not send the HSTS Strict-Transport-Security header, which makes it easier for man-in-the-middle attackers to hijack sessions or obtain sensitive information by leveraging the presence of HTTP requests.
nvd
CVE-2013-0553P4LOWCVSS 3.5v8.5.2.0v8.5.2.12013-04-28
CVE-2013-0553 [LOW] CVE-2013-0553: The client implementation in IBM Sametime 8.5.1 through 8.5.2.1, as used in Sametime Connect client, The client implementation in IBM Sametime 8.5.1 through 8.5.2.1, as used in Sametime Connect client, Sametime Advanced Connect client, Sametime Advanced Web client, and other products, allows remote authenticated users to send commands to individual chat users, or to all participants in a chat room, via a crafted Sametime Instant Message (IM).
nvd
CVE-2014-3014P4LOWCVSS 3.5v8.0.0.0v8.0.1.0+10 more2014-05-26
CVE-2014-3014 [LOW] CWE-79 CVE-2014-3014: Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 a Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-6743P4LOWCVSS 3.5v8.5.2.0v8.5.2.1+2 more2014-02-14
CVE-2013-6743 [LOW] CWE-79 CVE-2013-6743: Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IMG element.
nvd
Ibm Sametime vulnerabilities | cvebase