Ibm Sametime vulnerabilities
46 known vulnerabilities affecting ibm/sametime.
Total CVEs
46
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM34LOW9
Vulnerabilities
Page 3 of 3
CVE-2016-2974P4LOWCVSS 3.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2974 [LOW] CWE-200 CVE-2016-2974: IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose pote
IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934.
nvd
CVE-2016-2978P4LOWCVSS 3.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2978 [LOW] CWE-200 CVE-2016-2978: IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache loca
IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938.
nvd
CVE-2013-3984P4LOWCVSS 2.9v8.0.0.0v8.0.1.0+9 more2014-05-26
CVE-2013-3984 [LOW] CWE-200 CVE-2013-3984: The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not set the secu
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
nvd
CVE-2014-4747P4LOWCVSS 2.1v8.0.0.0v8.0.1.0+8 more2014-07-26
CVE-2014-4747 [LOW] CWE-200 CVE-2014-4747: The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers
The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting password hash by leveraging access to an unattended workstation to read HTML source code within a victim's browser.
nvd
CVE-2014-0890P4LOWCVSS 1.9v8.5.1.0v8.5.1.1+5 more2014-03-06
CVE-2014-0890 [LOW] CWE-255 CVE-2014-0890: The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a
The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration.realtime.telephony.*.level setting is used, logs cleartext passwords during Audio/Video chat sessions, which allows local users to obtain sensitive information by reading a log file.
nvd
CVE-2013-0534P4LOWCVSS 1.9v8.5.1v8.5.1.1+3 more2013-06-21
CVE-2013-0534 [LOW] CWE-255 CVE-2013-0534: The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, and 8.5.2.1, as used in the Lotus
The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, and 8.5.2.1, as used in the Lotus Notes client and separately, might allow local users to obtain sensitive information by leveraging the persistence of cleartext password strings within process memory.
nvd
← Previous3 / 3