Show filters
86 Total Results
Displaying 41-50 of 86
Sort by:
Attacker Value
Unknown
CVE-2016-2970
Disclosure Date: August 29, 2017 (last updated November 26, 2024)
IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers. IBM X-Force ID: 113851.
0
Attacker Value
Unknown
CVE-2014-4748
Disclosure Date: July 26, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown
CVE-2014-4747
Disclosure Date: July 26, 2014 (last updated October 05, 2023)
The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting password hash by leveraging access to an unattended workstation to read HTML source code within a victim's browser.
0
Attacker Value
Unknown
CVE-2014-3088
Disclosure Date: July 01, 2014 (last updated October 05, 2023)
stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST requests, which allows remote authenticated users to bypass intended upload restrictions by modifying the Content-Type header and file extension, as demonstrated by replacing a text/plain .txt upload with an application/octet-stream .exe upload.
0
Attacker Value
Unknown
CVE-2014-3867
Disclosure Date: May 26, 2014 (last updated October 05, 2023)
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2013-3984.
0
Attacker Value
Unknown
CVE-2013-3981
Disclosure Date: May 26, 2014 (last updated October 05, 2023)
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to download avatar photos of arbitrary users via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-3975
Disclosure Date: May 26, 2014 (last updated October 05, 2023)
Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to discover user names, full names, and e-mail addresses via a search.
0
Attacker Value
Unknown
CVE-2014-0906
Disclosure Date: May 26, 2014 (last updated October 05, 2023)
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not check whether a session cookie is current, which allows remote attackers to conduct user-search actions by leveraging possession of a (1) expired or (2) invalidated cookie.
0
Attacker Value
Unknown
CVE-2013-3977
Disclosure Date: May 26, 2014 (last updated October 05, 2023)
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge of valid user names.
0
Attacker Value
Unknown
CVE-2013-3980
Disclosure Date: May 26, 2014 (last updated October 05, 2023)
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to cause a denial of service (room unusability) by generating a large number of fictitious users to enter a meeting room.
0