CVE-2014-3867: Infoleak
Published May 26, 2014
·Updated
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2013-3984.
Affected Software
12 affected components
IBM Sametime=8.0.0.0
IBM Sametime=8.0.1.0
IBM Sametime=8.0.1.1
IBM Sametime=8.0.2.0
IBM Sametime=8.0.2.1
IBM Sametime=8.5.0.0
IBM Sametime=8.5.1.0
IBM Sametime=8.5.1.1
IBM Sametime=8.5.2.0
IBM Sametime=8.5.2.1
IBM Sametime=9.0.0.0
IBM Sametime=9.0.0.1
Event History
May 26, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·11:14 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3867?
CVE-2014-3867 is rated as a medium severity vulnerability.
2
How do I fix CVE-2014-3867?
To fix CVE-2014-3867, update your IBM Sametime application to the latest version that addresses this issue.
3
What versions of IBM Sametime are affected by CVE-2014-3867?
CVE-2014-3867 affects IBM Sametime versions from 8.0.0.0 to 9.0.0.1.
4
What type of vulnerability is CVE-2014-3867?
CVE-2014-3867 is an Information Disclosure vulnerability related to cookie handling.
5
Can CVE-2014-3867 be exploited remotely?
Yes, CVE-2014-3867 can be exploited remotely by attackers via script access.