CVE-2016-2976: Infoleak
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared sensitive information by viewing the meeting report history. IBM X-Force ID: 113936.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2976?
CVE-2016-2976 has a moderate severity level due to its potential exposure of previously cleared sensitive information.
How do I fix CVE-2016-2976?
To mitigate CVE-2016-2976, update to a patched version of HCL Sametime as released by IBM for the affected versions.
Who is affected by CVE-2016-2976?
CVE-2016-2976 affects users of IBM Sametime Meeting Server versions 8.5.2, 8.5.2.1, 9.0.0.0, 9.0.0.1, and 9.0.1.
What type of information can be exposed by CVE-2016-2976?
CVE-2016-2976 allows meeting invitees to access sensitive information that was previously cleared from the meeting report history.
Is CVE-2016-2976 a zero-day vulnerability?
CVE-2016-2976 is not classified as a zero-day vulnerability as it has been publicly disclosed and is being actively tracked.