CVE-2013-3985
2.9
Vector
AV:A/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 5.5 / Impact: 2.9
Source: NVD
Description
The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 does not properly restrict application cookies, which allows remote attackers to read session variables by leveraging a weak setting of the Domain variable.
Affected (2)
Products: Ibm: Lotus Sametime
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.5.2.1 |
Related CWEs
References (4)
Source: psirt@us.ibm.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.