Information Disclosure in IBM Lotus Sametime Configuration Servlet
CVE-2011-1370
Currently unrated
Summary
The Sametime configuration servlet (SCS) in IBM Lotus Sametime versions 7.0 to 8.5.2 has a security weakness due to its default configuration lacking an authentication requirement. This oversight permits remote attackers to exploit the servlet and gain unauthorized access to sensitive configuration settings by analyzing response messages. Organizations should ensure proper authentication is implemented to mitigate the risk of information exposure.
References
Timeline
Vulnerability published
Vulnerability Reserved