CVE-2016-2966: Infoleak
Published Aug 29, 2017
·Updated
IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing the meeting room id. IBM X-Force ID: 113847.
Affected Software
7 affected components
IBM Sametime=8.5.1.0
IBM Sametime=8.5.1.1
IBM Sametime=8.5.2.0
IBM Sametime=8.5.2.1
IBM Sametime=9.0.0.0
IBM Sametime=9.0.0.1
IBM Sametime=9.0.1
Remediation
Patch Available
Event History
Aug 29, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-2966?
CVE-2016-2966 has a moderate severity rating due to its potential for allowing authenticated users to enumerate meeting rooms.
2
How do I fix CVE-2016-2966?
To fix CVE-2016-2966, upgrade to the latest version of IBM Sametime that addresses this vulnerability.
3
Who is affected by CVE-2016-2966?
CVE-2016-2966 affects users of IBM Sametime versions 8.5.1, 8.5.2, and 9.0.
4
What can an attacker do with CVE-2016-2966?
An attacker can exploit CVE-2016-2966 to guess and enumerate meeting room IDs, potentially leading to unauthorized access.
5
Is CVE-2016-2966 a critical vulnerability?
CVE-2016-2966 is not classified as a critical vulnerability, but it poses a risk due to the potential for room enumeration.