IBM Sametime Connect Client CVE-2016-2974 Information Disclosure Vulnerability
BID:100528
CVE-2016-2974 |Info
IBM Sametime Connect Client CVE-2016-2974 Information Disclosure Vulnerability
| Bugtraq ID: | 100528 |
| Class: | Design Error |
| CVE: |
CVE-2016-2974 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 25 2017 12:00AM |
| Updated: | Aug 25 2017 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Sametime 9.0.1 IBM Sametime 9.0.0.1 IBM Sametime 9.0.0.0 IBM Sametime 8.5.2.1 IBM Sametime 8.5.2.0 |
| Not Vulnerable: |
IBM Sametime 9.0.1 FP1 |
Discussion
IBM Sametime Connect Client CVE-2016-2974 Information Disclosure Vulnerability
IBM Sametime Connect Client is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow attackers to obtain sensitive information from the application, that may aid in further attacks.
IBM Sametime 8.5.2, 8.5.2.1, 9.0, 9.0.0.1 and 9.0.1 are vulnerable.
IBM Sametime Connect Client is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow attackers to obtain sensitive information from the application, that may aid in further attacks.
IBM Sametime 8.5.2, 8.5.2.1, 9.0, 9.0.0.1 and 9.0.1 are vulnerable.
Exploit / POC
IBM Sametime Connect Client CVE-2016-2974 Information Disclosure Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
IBM Sametime Connect Client CVE-2016-2974 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Sametime Connect Client CVE-2016-2974 Information Disclosure Vulnerability
References:
References: