CVE-2013-3977: Medium severity IBM Sametime vulnerability
Published May 26, 2014
·Updated
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge of valid user names.
Affected Software
12 affected components
IBM Sametime=8.0.0.0
IBM Sametime=8.0.1.0
IBM Sametime=8.0.1.1
IBM Sametime=8.0.2.0
IBM Sametime=8.0.2.1
IBM Sametime=8.5.0.0
IBM Sametime=8.5.1.0
IBM Sametime=8.5.1.1
IBM Sametime=8.5.2.0
IBM Sametime=8.5.2.1
IBM Sametime=9.0.0.0
IBM Sametime=9.0.0.1
Event History
May 26, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·04:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-3977?
CVE-2013-3977 is classified as a low-severity vulnerability.
2
How do I fix CVE-2013-3977?
Fixing CVE-2013-3977 involves upgrading to a later version of IBM Sametime that addresses this vulnerability.
3
What systems are affected by CVE-2013-3977?
CVE-2013-3977 affects IBM Sametime versions 8.x through 8.5.2.1 and 9.x through 9.0.0.1.
4
What type of attack does CVE-2013-3977 enable?
CVE-2013-3977 allows remote attackers to identify meeting rooms owned by a user by using known valid usernames.
5
Is there any security impact associated with CVE-2013-3977?
Yes, CVE-2013-3977 can lead to information disclosure regarding meeting room ownership.