CVE-2013-6742: High severity IBM Sametime vulnerability
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6742?
CVE-2013-6742 has a medium severity level, as it could allow remote attackers to gain unauthorized access in certain conditions.
How do I fix CVE-2013-6742?
To mitigate CVE-2013-6742, ensure that the autocomplete attribute is set to 'off' for the password field in the application configuration.
Which versions of IBM Sametime are affected by CVE-2013-6742?
CVE-2013-6742 affects IBM Sametime versions 8.5.2 through 8.5.2.1 and 9.x up to 9.0.0.1.
What type of attack does CVE-2013-6742 facilitate?
CVE-2013-6742 facilitates unauthorized access through unattended workstations by exploiting the lack of an off autocomplete attribute in password fields.
Is there a way to check if my IBM Sametime is vulnerable to CVE-2013-6742?
You can identify if your IBM Sametime version is vulnerable to CVE-2013-6742 by verifying the installed version against the affected versions listed.