CVE-2016-2972: High severity hcl sametime vulnerability
IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2972?
CVE-2016-2972 is classified as a moderate severity vulnerability due to the potential exposure of user credentials.
How do I fix CVE-2016-2972?
To fix CVE-2016-2972, users should ensure they are using the latest version of the IBM Sametime Meeting Server and configure their browsers to clear local cache regularly.
What systems are affected by CVE-2016-2972?
CVE-2016-2972 affects IBM Sametime Meeting Server versions 8.5.2 and 9.0, including its subsequent updates.
What type of impact does CVE-2016-2972 have on users?
CVE-2016-2972 can lead to unauthorized access to user credentials stored in the browser cache by local users.
Is there a workaround for CVE-2016-2972?
A temporary workaround for CVE-2016-2972 is to manually log out of sessions and clear the browser cache after use.