CVE-2016-2978: Infoleak
Published Aug 29, 2017
·Updated
IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938.
Affected Software
5 affected components
IBM Sametime=8.5.2.0
IBM Sametime=8.5.2.1
IBM Sametime=9.0.0.0
IBM Sametime=9.0.0.1
IBM Sametime=9.0.1
Remediation
Patch Available
Event History
Aug 29, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-2978?
CVE-2016-2978 is rated as a moderate severity vulnerability due to the potential for sensitive information exposure.
2
How do I fix CVE-2016-2978?
To mitigate CVE-2016-2978, it is recommended to clear the browser cache regularly and apply any available updates to IBM Sametime.
3
Who is affected by CVE-2016-2978?
CVE-2016-2978 affects users of IBM Sametime versions 8.5.2, 8.5.2.1, and 9.0.0.0 through 9.0.1.
4
What type of information could be exposed in CVE-2016-2978?
CVE-2016-2978 could expose potentially sensitive information that is stored in the browser cache.
5
Is CVE-2016-2978 exploitable remotely?
CVE-2016-2978 is not exploitable remotely, as it requires local access to the affected installation.