← Back

CVE-2011-1370

nvd nist
Published: Oct 29, 2011Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authentication requirement, which allows remote attackers to read the configuration settings by examining a response message.

Affected (12)

Products: Ibm: Lotus Sametime
1 product
Lotus Sametime
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.0
Version 7.5.0.1
Version 7.5.1.1
Version 7.5.1.2
Version 7.5.1
Version 7.5
Version 8.0.1
Version 8.0.2
Version 8.0
Version 8.5.1
Version 8.5.2
Version 8.5

Related CWEs

Timeline

No history available yet.