First published: Fri Aug 03 2007(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Lotus Sametime Server 7.5.1 before 20070731 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a crafted Sametime meeting.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sametime | <=7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4142 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To address CVE-2007-4142, it is recommended to upgrade IBM Lotus Sametime to a version later than 7.5.1 or apply relevant security patches.
CVE-2007-4142 affects IBM Lotus Sametime versions up to 7.5.1, specifically those prior to July 31, 2007.
The vulnerability in CVE-2007-4142 allows remote attackers to execute arbitrary web scripts or HTML in the context of the affected application.
While upgrading is the best solution, temporary measures include monitoring user input and sanitizing it to mitigate potential XSS attacks.