IBM Sametime Meeting Server CVE-2016-2970 Information Disclosure Vulnerability
BID:100529
CVE-2016-2970 |Info
IBM Sametime Meeting Server CVE-2016-2970 Information Disclosure Vulnerability
| Bugtraq ID: | 100529 |
| Class: | Input Validation Error |
| CVE: |
CVE-2016-2970 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2017 12:00AM |
| Updated: | Aug 23 2017 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Sametime 9.0.1 IBM Sametime 9.0.0.1 IBM Sametime 9.0.0.0 IBM Sametime 8.5.2.1 IBM Sametime 8.5.2.0 |
| Not Vulnerable: |
IBM Sametime 9.0.1 FP1 |
Discussion
IBM Sametime Meeting Server CVE-2016-2970 Information Disclosure Vulnerability
IBM Sametime Meeting Server is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to disclose sensitive information. Information obtained may lead to further attacks.
IBM Sametime 8.5.2, 8.5.2.1, 9.0, 9.0.0.1 and 9.0.1 are vulnerable.
IBM Sametime Meeting Server is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to disclose sensitive information. Information obtained may lead to further attacks.
IBM Sametime 8.5.2, 8.5.2.1, 9.0, 9.0.0.1 and 9.0.1 are vulnerable.
Exploit / POC
IBM Sametime Meeting Server CVE-2016-2970 Information Disclosure Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
IBM Sametime Meeting Server CVE-2016-2970 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Sametime Meeting Server CVE-2016-2970 Information Disclosure Vulnerability
References:
References: