CVE-2016-2980: Medium severity IBM Sametime vulnerability
Published Aug 29, 2017
·Updated
The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Force ID: 113993.
Affected Software
5 affected components
IBM Sametime=8.5.2.0
IBM Sametime=8.5.2.1
IBM Sametime=9.0.0.0
IBM Sametime=9.0.0.1
IBM Sametime=9.0.1
Remediation
Patch Available
Event History
Aug 29, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-2980?
CVE-2016-2980 has been classified as a high severity vulnerability due to the potential for script injection attacks.
2
How do I fix CVE-2016-2980?
To address CVE-2016-2980, you should upgrade to a patched version of the HCL Sametime software.
3
Which versions are affected by CVE-2016-2980?
CVE-2016-2980 affects HCL Sametime versions 8.5.2.0, 8.5.2.1, 9.0.0.0, 9.0.0.1, and 9.0.1.
4
What type of attack can exploit CVE-2016-2980?
CVE-2016-2980 can be exploited through a malicious site injecting harmful scripts into HCL Sametime's WebPlayer.
5
Is there a workaround for CVE-2016-2980 if I can’t upgrade?
No official workaround for CVE-2016-2980 has been provided; upgrading to a fixed version is the recommended solution.