CVE-2016-2977: Input Validation
Published Aug 29, 2017
·Updated
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in the meeting. IBM X-Force ID: 113937.
Affected Software
5 affected components
IBM Sametime=8.5.2.0
IBM Sametime=8.5.2.1
IBM Sametime=9.0.0.0
IBM Sametime=9.0.0.1
IBM Sametime=9.0.1
Remediation
Patch Available
Event History
Aug 29, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-2977?
CVE-2016-2977 has a moderate severity level due to its potential disruption of user control in meetings.
2
How do I fix CVE-2016-2977?
Resolving CVE-2016-2977 involves updating to the latest version of the IBM Sametime Meeting Server where the vulnerability is addressed.
3
What versions of IBM Sametime are affected by CVE-2016-2977?
CVE-2016-2977 affects IBM Sametime Meeting Server versions 8.5.2.0, 8.5.2.1, 9.0.0.0, 9.0.0.1, and 9.0.1.
4
What is the impact of CVE-2016-2977 on users?
The impact of CVE-2016-2977 allows a malicious user to disrupt meeting controls by lowering the raised hands of other users.
5
Is there a workaround for CVE-2016-2977?
Currently, there are no documented workarounds for CVE-2016-2977; updating software is the recommended action.