First published: Tue Aug 29 2017(Updated: )
IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious link, a remote attacker could force the user to log out of Sametime. IBM X-Force ID: 113846.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Sametime | =8.5.2.0 | |
HCL Sametime | =8.5.2.1 | |
HCL Sametime | =9.0.0.0 | |
HCL Sametime | =9.0.0.1 | |
HCL Sametime | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2965 has a medium severity rating due to its potential for cross-site request forgery attacks.
To mitigate CVE-2016-2965, ensure that users are advised against clicking on suspicious links and review IBM's security patches.
CVE-2016-2965 affects IBM Sametime Meeting Server versions 8.5.2 and 9.0.
While CVE-2016-2965 itself does not allow unauthorized access, it can disrupt user sessions by forcing a logout.
A valid workaround for CVE-2016-2965 includes educating users about the risks of unknown links and enabling additional security measures.