IBM Sametime Connect CVE-2014-0890 Information Disclosure Vulnerability
BID:65937
Info
IBM Sametime Connect CVE-2014-0890 Information Disclosure Vulnerability
| Bugtraq ID: | 65937 |
| Class: | Design Error |
| CVE: |
CVE-2014-0890 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 04 2014 12:00AM |
| Updated: | Mar 04 2014 12:00AM |
| Credit: | Adriano Marcio Monteiro |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM Sametime Connect CVE-2014-0890 Information Disclosure Vulnerability
IBM Sametime Connect is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow attackers to obtain sensitive information from the application, that may aid in further attacks.
IBM Sametime Connect 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0 and 9.0.0.1 are vulnerable.
IBM Sametime Connect is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow attackers to obtain sensitive information from the application, that may aid in further attacks.
IBM Sametime Connect 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0 and 9.0.0.1 are vulnerable.
Exploit / POC
IBM Sametime Connect CVE-2014-0890 Information Disclosure Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
IBM Sametime Connect CVE-2014-0890 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Sametime Connect CVE-2014-0890 Information Disclosure Vulnerability
References:
References:
- IBM Homepage (IBM)