First published: Tue Aug 29 2017(Updated: )
IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Sametime | =8.5.2.0 | |
HCL Sametime | =8.5.2.1 | |
HCL Sametime | =9.0.0.0 | |
HCL Sametime | =9.0.0.1 | |
HCL Sametime | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2974 has been classified as a moderate severity vulnerability due to information disclosure risks.
To mitigate CVE-2016-2974, ensure that the IBM Sametime Rich Client is properly uninstalled and access controls are enforced on the local machine.
CVE-2016-2974 affects IBM Sametime Connect versions 8.5.2, 8.5.2.1, 9.0, 9.0.0.1, and 9.0.1.
CVE-2016-2974 could disclose potentially sensitive information related to the Sametime environment and other local users on the machine.
There is no specific patch for CVE-2016-2974, but users are advised to follow best practices for uninstallation and data protection.