CVE-2016-2964: Infoleak
Published Aug 29, 2017
·Updated
IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too detailed and may reveal details about the application. IBM X-Force ID: 113813.
Affected Software
5 affected components
IBM Sametime=8.5.2.0
IBM Sametime=8.5.2.1
IBM Sametime=9.0.0.0
IBM Sametime=9.0.0.1
IBM Sametime=9.0.1
Remediation
Patch Available
Event History
Aug 29, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-2964?
CVE-2016-2964 is rated as medium severity due to potential information disclosure risks.
2
How do I fix CVE-2016-2964?
To fix CVE-2016-2964, upgrade to a newer version of IBM Sametime where this vulnerability is addressed.
3
What causes CVE-2016-2964?
CVE-2016-2964 is caused by IBM Sametime providing overly detailed error messages that can expose application internals.
4
What are the affected versions for CVE-2016-2964?
CVE-2016-2964 impacts IBM Sametime versions 8.5.2.0, 8.5.2.1, 9.0.0.0, 9.0.0.1, and 9.0.1.
5
Is there a workaround for CVE-2016-2964?
Currently, there are no publicized workarounds for CVE-2016-2964 other than upgrading to secure versions.