CVE-2014-4747: Infoleak
Published Jul 26, 2014
·Updated
The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting password hash by leveraging access to an unattended workstation to read HTML source code within a victim's browser.
Affected Software
10 affected components
IBM Sametime=8.0.0.0
IBM Sametime=8.0.1.0
IBM Sametime=8.0.1.1
IBM Sametime=8.0.2.0
IBM Sametime=8.0.2.1
IBM Sametime=8.5.0.0
IBM Sametime=8.5.1.0
IBM Sametime=8.5.1.1
IBM Sametime=8.5.2.0
IBM Sametime=8.5.2.1
Event History
Jul 26, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4747?
CVE-2014-4747 has been classified as a low severity vulnerability.
2
How do I fix CVE-2014-4747?
To fix CVE-2014-4747, ensure all unattended workstations are locked when not in use.
3
What is the impact of CVE-2014-4747?
The impact of CVE-2014-4747 allows local attackers to discover meeting password hashes.
4
Which versions of IBM Sametime are affected by CVE-2014-4747?
IBM Sametime versions 8.x through 8.5.2.1 are affected by CVE-2014-4747.
5
How can I mitigate the risk of CVE-2014-4747?
Mitigating the risk of CVE-2014-4747 includes enforcing physical security and user training on security practices.