Information Disclosure Vulnerability in IBM Sametime Meeting Server
CVE-2016-2969

4.3MEDIUM

Key Information:

Vendor
IBM
Status
Vendor
CVE Published:
29 August 2017

Summary

The IBM Sametime Meeting Server versions 8.5.2 and 9.0 are susceptible to an information disclosure vulnerability, where replies may inadvertently include email addresses of individuals not intended to be part of the conversation. This security flaw can lead to unauthorized exposure of sensitive contact information, putting users at risk. Organizations using these versions should consider applying appropriate remediation measures to safeguard user privacy.

Affected Version(s)

Sametime 8.5.2

Sametime 8.5.2.1

Sametime 9.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.