First published: Tue Aug 29 2017(Updated: )
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Sametime | =8.5.2.0 | |
HCL Sametime | =8.5.2.1 | |
HCL Sametime | =9.0.0.0 | |
HCL Sametime | =9.0.0.1 | |
HCL Sametime | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0354 is classified as a medium severity vulnerability due to its ability to allow authenticated users to upload malicious files.
To fix CVE-2016-0354, update your IBM Sametime Enterprise Meeting Server to the latest patched version available from IBM.
CVE-2016-0354 affects users of IBM Sametime versions 8.5.2 and 9.0, including specific releases within those versions.
The potential impacts of CVE-2016-0354 include unauthorized file execution with user privileges, leading to possible data compromise.
CVE-2016-0354 is exploitable by authenticated users within the meeting room, which poses a risk to unsuspecting participants.