Page 4 of 52 results (0.003 seconds)

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855. IBM Sametime Meeting Server v8.5.2 y v9.0 podría almacenar credenciales de un usuario de Sametime Meetings en la memoria caché local de su navegador, pudiendo un usuario local acceder a ellas. IBM X-Force ID: 113855. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/113855 • CWE-255: Credentials Management Errors •

CVSS: 6.0EPSS: 0%CPEs: 5EXPL: 0

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893. IBM Sametime Enterprise Meeting Server 8.5.2 y 9.0 podría permitir que un usuario autenticado suba un archivo malicioso a la sala de reuniones de Sametime, pudiendo los usuarios descargarlo y ejecutarlo sin necesitar privilegios de usuario. IBM X-Force ID: 111893. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/111893 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 4.3EPSS: 0%CPEs: 5EXPL: 0

IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. IBM X-Force ID: 113803. IBM Sametime Meeting Server 8.5.2 y 9.0 podría permitir que un usuario autenticado e invitado de una reunión Sametime bajase algunas o todas las manos de una reunión virtual, suplantando los resultados de los votos de una reunión. IBM X-Force ID: 113803. • http://www.ibm.com/support/docview.wss?uid=swg22006439 https://exchange.xforce.ibmcloud.com/vulnerabilities/113803 • CWE-20: Improper Input Validation •

CVSS: 4.3EPSS: 0%CPEs: 5EXPL: 0

IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges. IBM X-Force ID: 113804. IBM Sametime Meeting Server 8.5.2 y 9.0 podría permitir que un administrador de sala de reuniones elimine los privilegios de los administradores principales. IBM X-Force ID: 113804. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/113804 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 6.5EPSS: 0%CPEs: 5EXPL: 0

IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious link, a remote attacker could force the user to log out of Sametime. IBM X-Force ID: 113846. IBM Sametime 8.5.2 y 9.0 es vulnerable a ataques de Cross-Site Request Forgery (CSRF) a causa de una validación incorrecta de entradas proporcionadas por el usuario. Si se persuade a un usuario para que visite un link malicioso, un atacante remoto podría forzar al usuario a cerrar su sesión de Sametime. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/113846 • CWE-352: Cross-Site Request Forgery (CSRF) •