CVE-2016-2967: XSS
IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Sametime away message altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113848.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2967?
CVE-2016-2967 is considered a high severity vulnerability due to its potential for credential disclosure.
How do I fix CVE-2016-2967?
To mitigate CVE-2016-2967, users should upgrade to the latest versions of IBM Sametime which contain the security patch.
What types of attacks can CVE-2016-2967 enable?
CVE-2016-2967 can enable cross-site scripting (XSS) attacks, allowing attackers to execute arbitrary JavaScript in a user's session.
Which versions of IBM Sametime are affected by CVE-2016-2967?
CVE-2016-2967 affects IBM Sametime versions 8.5.2.0, 8.5.2.1, 9.0.0.0, 9.0.0.1, and 9.0.1.
Who is impacted by CVE-2016-2967?
Users of affected IBM Sametime versions are at risk, particularly those who use the away message feature.