CVE-2013-3977
IBM Sametime - Authentication Bypass
Title source: ruleDescription
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge of valid user names.
Exploits (1)
metasploit
SCANNER
by kicks4kittens · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/ibm_sametime_room_brute.rb
Scores
EPSS
0.2913
EPSS Percentile
96.5%
Classification
CWE
CWE-287
Status
draft
Affected Products (12)
ibm/sametime
ibm/sametime
ibm/sametime
ibm/sametime
ibm/sametime
ibm/sametime
ibm/sametime
ibm/sametime
ibm/sametime
ibm/sametime
ibm/sametime
ibm/sametime
Timeline
Published
May 26, 2014
Tracked Since
Feb 18, 2026