CVE-2016-2974: Infoleak
IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2974?
CVE-2016-2974 has been classified as a moderate severity vulnerability due to information disclosure risks.
How can I mitigate CVE-2016-2974?
To mitigate CVE-2016-2974, ensure that the IBM Sametime Rich Client is properly uninstalled and access controls are enforced on the local machine.
What versions are affected by CVE-2016-2974?
CVE-2016-2974 affects IBM Sametime Connect versions 8.5.2, 8.5.2.1, 9.0, 9.0.0.1, and 9.0.1.
What type of information could be disclosed due to CVE-2016-2974?
CVE-2016-2974 could disclose potentially sensitive information related to the Sametime environment and other local users on the machine.
Is there a patch available for CVE-2016-2974?
There is no specific patch for CVE-2016-2974, but users are advised to follow best practices for uninstallation and data protection.