CVE-2013-3046
4.3
Vector
AV:A/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 5.5 / Impact: 4.9
Source: NVD
Description
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not send the HSTS Strict-Transport-Security header, which makes it easier for man-in-the-middle attackers to hijack sessions or obtain sensitive information by leveraging the presence of HTTP requests.
Affected (12)
References (4)
Source: psirt@us.ibm.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.