First published: Fri Feb 14 2014(Updated: )
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwanted caching by a web browser, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Sametime | =8.5.2.0 | |
HCL Sametime | =8.5.2.1 | |
HCL Sametime | =9.0.0.0 | |
HCL Sametime | =9.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3978 has a severity rating that indicates a moderate risk due to information disclosure vulnerabilities.
To fix CVE-2013-3978, update to the latest version of HCL Sametime that addresses this cache-related issue.
The affected versions of HCL Sametime include 8.5.2.0, 8.5.2.1, 9.0.0.0, and 9.0.0.1.
CVE-2013-3978 is an information disclosure vulnerability due to improper HTTP response header management.
Remote attackers can exploit CVE-2013-3978 by leveraging unattended workstations to access sensitive information.