CVE-2013-3983: Input Validation
Published Feb 13, 2014
·Updated
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redirects, which has unspecified impact and remote attack vectors.
Affected Software
4 affected components
IBM Sametime=8.5.2.0
IBM Sametime=8.5.2.1
IBM Sametime=9.0.0.0
IBM Sametime=9.0.0.1
Event History
Feb 13, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3983?
CVE-2013-3983 is classified as having unspecified severity, indicating potential risks related to URL validation in redirects.
2
How do I fix CVE-2013-3983?
To fix CVE-2013-3983, it is recommended to update to the latest version of IBM Sametime that addresses this vulnerability.
3
What versions of IBM Sametime are affected by CVE-2013-3983?
CVE-2013-3983 affects IBM Sametime versions 8.5.2.0, 8.5.2.1, 9.0.0.0, and 9.0.0.1.
4
What vulnerabilities are associated with CVE-2013-3983?
CVE-2013-3983 is associated with security issues related to insufficient URL validation in Cookie headers.
5
Can CVE-2013-3983 be exploited remotely?
Yes, CVE-2013-3983 has remote attack vectors due to the lack of validation in redirects.