CVE-2011-1370: Medium severity ibm sametime vulnerability
The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authentication requirement, which allows remote attackers to read the configuration settings by examining a response message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1370?
CVE-2011-1370 is considered a medium severity vulnerability due to its ability to allow unauthorized access to sensitive configuration settings.
How do I fix CVE-2011-1370?
To fix CVE-2011-1370, configure the Sametime configuration servlet to require authentication to access its settings.
What are the affected versions for CVE-2011-1370?
CVE-2011-1370 affects IBM Lotus Sametime versions 7.0 through 8.5.2.
Can CVE-2011-1370 be exploited remotely?
Yes, CVE-2011-1370 can be exploited remotely without requiring authentication.
What impact does CVE-2011-1370 have on system security?
CVE-2011-1370 potentially allows attackers to read sensitive configuration data, which could lead to further exploitation of the system.