Show filters
40 Total Results
Displaying 21-30 of 40
Sort by:
Attacker Value
Unknown

CVE-2016-2979

Disclosure Date: August 29, 2017 (last updated November 26, 2024)
IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113945.
0
Attacker Value
Unknown

CVE-2016-2970

Disclosure Date: August 29, 2017 (last updated November 26, 2024)
IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers. IBM X-Force ID: 113851.
0
Attacker Value
Unknown

CVE-2014-3867

Disclosure Date: May 26, 2014 (last updated October 05, 2023)
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2013-3984.
0
Attacker Value
Unknown

CVE-2013-3981

Disclosure Date: May 26, 2014 (last updated October 05, 2023)
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to download avatar photos of arbitrary users via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-3975

Disclosure Date: May 26, 2014 (last updated October 05, 2023)
Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to discover user names, full names, and e-mail addresses via a search.
0
Attacker Value
Unknown

CVE-2014-0906

Disclosure Date: May 26, 2014 (last updated October 05, 2023)
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not check whether a session cookie is current, which allows remote attackers to conduct user-search actions by leveraging possession of a (1) expired or (2) invalidated cookie.
0
Attacker Value
Unknown

CVE-2013-3977

Disclosure Date: May 26, 2014 (last updated October 05, 2023)
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge of valid user names.
0
Attacker Value
Unknown

CVE-2013-3980

Disclosure Date: May 26, 2014 (last updated October 05, 2023)
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to cause a denial of service (room unusability) by generating a large number of fictitious users to enter a meeting room.
0
Attacker Value
Unknown

CVE-2014-3014

Disclosure Date: May 26, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown

CVE-2013-3046

Disclosure Date: May 26, 2014 (last updated October 05, 2023)
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not send the HSTS Strict-Transport-Security header, which makes it easier for man-in-the-middle attackers to hijack sessions or obtain sensitive information by leveraging the presence of HTTP requests.
0