First published: Fri Aug 25 2017(Updated: )
The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Force ID: 113993.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Sametime | =8.5.2.0 | |
HCL Sametime | =8.5.2.1 | |
HCL Sametime | =9.0.0.0 | |
HCL Sametime | =9.0.0.1 | |
HCL Sametime | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2980 has been classified as a high severity vulnerability due to the potential for script injection attacks.
To address CVE-2016-2980, you should upgrade to a patched version of the HCL Sametime software.
CVE-2016-2980 affects HCL Sametime versions 8.5.2.0, 8.5.2.1, 9.0.0.0, 9.0.0.1, and 9.0.1.
CVE-2016-2980 can be exploited through a malicious site injecting harmful scripts into HCL Sametime's WebPlayer.
No official workaround for CVE-2016-2980 has been provided; upgrading to a fixed version is the recommended solution.