cbcvebase.

Ibm Sametime vulnerabilities

46 known vulnerabilities affecting ibm/sametime.

Total CVEs
46
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM34LOW9

Vulnerabilities

Page 3 of 3
CVE-2016-2974P4LOWCVSS 3.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2974 [LOW] CWE-200 CVE-2016-2974: IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose pote IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934.
nvd
CVE-2016-2978P4LOWCVSS 3.3v8.5.2.0v8.5.2.1+5 more2017-08-29
CVE-2016-2978 [LOW] CWE-200 CVE-2016-2978: IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache loca IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938.
nvd
CVE-2013-3984P4LOWCVSS 2.9v8.0.0.0v8.0.1.0+9 more2014-05-26
CVE-2013-3984 [LOW] CWE-200 CVE-2013-3984: The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not set the secu The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
nvd
CVE-2014-4747P4LOWCVSS 2.1v8.0.0.0v8.0.1.0+8 more2014-07-26
CVE-2014-4747 [LOW] CWE-200 CVE-2014-4747: The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting password hash by leveraging access to an unattended workstation to read HTML source code within a victim's browser.
nvd
CVE-2014-0890P4LOWCVSS 1.9v8.5.1.0v8.5.1.1+5 more2014-03-06
CVE-2014-0890 [LOW] CWE-255 CVE-2014-0890: The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration.realtime.telephony.*.level setting is used, logs cleartext passwords during Audio/Video chat sessions, which allows local users to obtain sensitive information by reading a log file.
nvd
CVE-2013-0534P4LOWCVSS 1.9v8.5.1v8.5.1.1+3 more2013-06-21
CVE-2013-0534 [LOW] CWE-255 CVE-2013-0534: The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, and 8.5.2.1, as used in the Lotus The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, and 8.5.2.1, as used in the Lotus Notes client and separately, might allow local users to obtain sensitive information by leveraging the persistence of cleartext password strings within process memory.
nvd
Ibm Sametime vulnerabilities | cvebase