Session Variable Exposure in IBM Lotus Sametime Enterprise Meeting Server
CVE-2013-3985
Currently unrated
Summary
The Enterprise Meeting Server in IBM Lotus Sametime versions 8.5.2 and 8.5.2.1 comes with a vulnerability that stems from inadequate restrictions on application cookies. As a result, a remote attacker could exploit a weakly configured Domain variable, potentially enabling them to read and access sensitive session variables. This flaw underscores the importance of proper cookie management to ensure user session integrity and security.
References
Timeline
Vulnerability published
Vulnerability Reserved