CVE-2016-2975: XSS
IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113935.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2975?
CVE-2016-2975 is considered a moderate severity vulnerability due to the potential for cross-site scripting attacks.
How can I fix CVE-2016-2975?
To fix CVE-2016-2975, users should upgrade to the latest version of IBM Sametime that addresses the cross-site scripting vulnerability.
Which versions of IBM Sametime are affected by CVE-2016-2975?
CVE-2016-2975 affects IBM Sametime versions 8.5.2, 8.5.2.1, 9.0.0, 9.0.0.1, and 9.0.1.
What are the potential consequences of CVE-2016-2975?
The potential consequences of CVE-2016-2975 include unauthorized access to user credentials and altered application functionality.
Is CVE-2016-2975 a critical vulnerability?
CVE-2016-2975 is not classified as critical but poses a significant risk due to its potential impact on user data and session integrity.