IBM Sametime Meeting Server 'autocomplete' Attribute Security Bypass Vulnerability
BID:65608
Info
IBM Sametime Meeting Server 'autocomplete' Attribute Security Bypass Vulnerability
| Bugtraq ID: | 65608 |
| Class: | Design Error |
| CVE: |
CVE-2013-6742 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 14 2014 12:00AM |
| Updated: | Feb 14 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
IBM Sametime Meeting Server 9.0.0.1 IBM Sametime Meeting Server 8.5.2.1 IBM Sametime Meeting Server 8.5.2 |
| Not Vulnerable: | |
Discussion
IBM Sametime Meeting Server 'autocomplete' Attribute Security Bypass Vulnerability
IBM Sametime Meeting Server is prone to a security-bypass vulnerability.
Successfully exploiting this issue allows attackers to gain unauthorized access to the affected application. This may lead to further attacks.
IBM Sametime Meeting Server versions 8.5.2, 8.5.2.1, and 9.0.0.1 are vulnerable.
IBM Sametime Meeting Server is prone to a security-bypass vulnerability.
Successfully exploiting this issue allows attackers to gain unauthorized access to the affected application. This may lead to further attacks.
IBM Sametime Meeting Server versions 8.5.2, 8.5.2.1, and 9.0.0.1 are vulnerable.
Exploit / POC
IBM Sametime Meeting Server 'autocomplete' Attribute Security Bypass Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.