Information Disclosure in IBM Lotus Sametime Configuration Servlet
CVE-2011-1370

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
29 October 2011

Summary

The Sametime configuration servlet (SCS) in IBM Lotus Sametime versions 7.0 to 8.5.2 has a security weakness due to its default configuration lacking an authentication requirement. This oversight permits remote attackers to exploit the servlet and gain unauthorized access to sensitive configuration settings by analyzing response messages. Organizations should ensure proper authentication is implemented to mitigate the risk of information exposure.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.