First published: Tue Aug 29 2017(Updated: )
IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Sametime | =8.5.2.0 | |
HCL Sametime | =8.5.2.1 | |
HCL Sametime | =9.0.0.0 | |
HCL Sametime | =9.0.0.1 | |
HCL Sametime | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2972 is classified as a moderate severity vulnerability due to the potential exposure of user credentials.
To fix CVE-2016-2972, users should ensure they are using the latest version of the IBM Sametime Meeting Server and configure their browsers to clear local cache regularly.
CVE-2016-2972 affects IBM Sametime Meeting Server versions 8.5.2 and 9.0, including its subsequent updates.
CVE-2016-2972 can lead to unauthorized access to user credentials stored in the browser cache by local users.
A temporary workaround for CVE-2016-2972 is to manually log out of sessions and clear the browser cache after use.