Information Disclosure Vulnerability in IBM Sametime Meeting Server
CVE-2016-2969
4.3MEDIUM
Summary
The IBM Sametime Meeting Server versions 8.5.2 and 9.0 are susceptible to an information disclosure vulnerability, where replies may inadvertently include email addresses of individuals not intended to be part of the conversation. This security flaw can lead to unauthorized exposure of sensitive contact information, putting users at risk. Organizations using these versions should consider applying appropriate remediation measures to safeguard user privacy.
Affected Version(s)
Sametime 8.5.2
Sametime 8.5.2.1
Sametime 9.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved