IBM Sametime Meeting Server CVE-2013-3988 Clickjacking Vulnerability
BID:65613
Info
IBM Sametime Meeting Server CVE-2013-3988 Clickjacking Vulnerability
| Bugtraq ID: | 65613 |
| Class: | Design Error |
| CVE: |
CVE-2013-3988 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2014 12:00AM |
| Updated: | Feb 06 2014 12:00AM |
| Credit: | Chris John Riley of the R-IT Cert. |
| Vulnerable: |
IBM Sametime Meeting Server 9.0.0.1 IBM Sametime Meeting Server 9.0.0 IBM Sametime Meeting Server 8.5.2.1 IBM Sametime Meeting Server 8.5.2 |
| Not Vulnerable: | |
Discussion
IBM Sametime Meeting Server CVE-2013-3988 Clickjacking Vulnerability
IBM Sametime Meeting Server is prone to a clickjacking vulnerability because it fails to perform validity checks on certain user actions through HTTP requests.
Successful exploits will allow an attacker to compromise the affected application or obtain sensitive information. Other attacks are also possible.
IBM Sametime Meeting Server versions 8.5.2, 8.5.2.1, 9.0.0 and 9.0.0.1 are vulnerable.
IBM Sametime Meeting Server is prone to a clickjacking vulnerability because it fails to perform validity checks on certain user actions through HTTP requests.
Successful exploits will allow an attacker to compromise the affected application or obtain sensitive information. Other attacks are also possible.
IBM Sametime Meeting Server versions 8.5.2, 8.5.2.1, 9.0.0 and 9.0.0.1 are vulnerable.