www-01.ibm.comConfirmation
http://www-01.ibm.com/support/docview.wss?uid=swg21671201 CVE-2013-3977
IBM Lotus Notes Sametime Room Name Bruteforce
Record summary
CVE-2013-3977 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge of valid user names.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
MetasploitIBM Lotus Notes Sametime Room Name BruteforceMetasploit auxiliary PoCby kicks4kittensNot analyzed1 file
References
3sametime-cve20133977-info-disc(84901)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/84901 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-3977