Session Variable Exposure in IBM Lotus Sametime Enterprise Meeting Server
CVE-2013-3985
Currently unrated
What is CVE-2013-3985?
The Enterprise Meeting Server in IBM Lotus Sametime versions 8.5.2 and 8.5.2.1 comes with a vulnerability that stems from inadequate restrictions on application cookies. As a result, a remote attacker could exploit a weakly configured Domain variable, potentially enabling them to read and access sensitive session variables. This flaw underscores the importance of proper cookie management to ensure user session integrity and security.