First published: Tue Aug 29 2017(Updated: )
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111895.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Sametime | =8.5.2.0 | |
HCL Sametime | =8.5.2.1 | |
HCL Sametime | =9.0.0.0 | |
HCL Sametime | =9.0.0.1 | |
HCL Sametime | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0356 has a medium severity rating, indicating potential risk to system integrity when exploited.
To fix CVE-2016-0356, update to the latest version of HCL Sametime that includes patches addressing this vulnerability.
CVE-2016-0356 affects users of IBM Sametime Enterprise Meeting Server versions 8.5.2 and 9.0.
CVE-2016-0356 involves a cross-site request forgery (CSRF) attack that can disrupt screen sharing in meeting rooms.
Yes, an attacker can exploit CVE-2016-0356 during a meeting if an invited authenticated user is present.