CVE-2016-0354: Malicious File Upload
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0354?
CVE-2016-0354 is classified as a medium severity vulnerability due to its ability to allow authenticated users to upload malicious files.
How do I fix CVE-2016-0354?
To fix CVE-2016-0354, update your IBM Sametime Enterprise Meeting Server to the latest patched version available from IBM.
Who is affected by CVE-2016-0354?
CVE-2016-0354 affects users of IBM Sametime versions 8.5.2 and 9.0, including specific releases within those versions.
What are the potential impacts of CVE-2016-0354?
The potential impacts of CVE-2016-0354 include unauthorized file execution with user privileges, leading to possible data compromise.
Is CVE-2016-0354 exploitable remotely?
CVE-2016-0354 is exploitable by authenticated users within the meeting room, which poses a risk to unsuspecting participants.