CVE-2011-1370
Summary
| CVE | CVE-2011-1370 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-10-29 10:55:08 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authentication requirement, which allows remote attackers to read the configuration settings by examining a response message. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Lotus Sametime | 7.0 | All | All | All |
| Application | Ibm | Lotus Sametime | 7.5 | All | All | All |
| Application | Ibm | Lotus Sametime | 7.5.0.1 | All | All | All |
| Application | Ibm | Lotus Sametime | 7.5.1 | All | All | All |
| Application | Ibm | Lotus Sametime | 7.5.1.1 | All | All | All |
| Application | Ibm | Lotus Sametime | 7.5.1.2 | All | All | All |
| Application | Ibm | Lotus Sametime | 8.0 | All | All | All |
| Application | Ibm | Lotus Sametime | 8.0.1 | All | All | All |
| Application | Ibm | Lotus Sametime | 8.0.2 | All | All | All |
| Application | Ibm | Lotus Sametime | 8.5 | All | All | All |
| Application | Ibm | Lotus Sametime | 8.5.1 | All | All | All |
| Application | Ibm | Lotus Sametime | 8.5.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Security Bulletin: Potential Security Exposure in IBM Lotus Sametime Configuration Servlet (CVE-2011-1370) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.