CVE-2016-2972
https://notcve.org/view.php?id=CVE-2016-2972
IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855. IBM Sametime Meeting Server v8.5.2 y v9.0 podría almacenar credenciales de un usuario de Sametime Meetings en la memoria caché local de su navegador, pudiendo un usuario local acceder a ellas. IBM X-Force ID: 113855. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/113855 • CWE-255: Credentials Management Errors •
CVE-2016-0356
https://notcve.org/view.php?id=CVE-2016-0356
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111895. IBM Sametime Enterprise Meeting Server 8.5.2 y 9.0 podría permitir que un usuario autenticado que haya sido invitado a una sala de reuniones de Sametimed etenga la compartición de pantalla mediante Cross-Site Request Forgery (CSRF). IBM X-Force ID: 111895. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/111895 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2016-2965
https://notcve.org/view.php?id=CVE-2016-2965
IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious link, a remote attacker could force the user to log out of Sametime. IBM X-Force ID: 113846. IBM Sametime 8.5.2 y 9.0 es vulnerable a ataques de Cross-Site Request Forgery (CSRF) a causa de una validación incorrecta de entradas proporcionadas por el usuario. Si se persuade a un usuario para que visite un link malicioso, un atacante remoto podría forzar al usuario a cerrar su sesión de Sametime. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/113846 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2016-2971
https://notcve.org/view.php?id=CVE-2016-2971
IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. IBM X-Force ID: 113898. IBM Sametime Media Services 8.5.2 y 9.0 puede divulgar información sensible en registros de errores de seguimiento de pila que podría ayudar a un atacante en futuros ataques. IBM X-Force ID: 113898. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/113898 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-2969
https://notcve.org/view.php?id=CVE-2016-2969
IBM Sametime Meeting Server 8.5.2 and 9.0 may send replies that contain emails of people that should not be in these messages. IBM X-Force ID: 113850. IBM Sametime Media Services 8.5.2 y 9.0 puede enviar respuestas que contengan emails de personas que no deberían estar en esos mensajes. IBM X-Force ID: 113850. • http://www.ibm.com/support/docview.wss?uid=swg22006439 http://www.securityfocus.com/bid/100599 http://www.securitytracker.com/id/1039231 https://exchange.xforce.ibmcloud.com/vulnerabilities/113850 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •