CVE-2013-3985

IBM Lotus Sametime 8.5.2-8.5.2.1 - Session Variable Exposure via Weak Cookie Domain Setting

Title source: llm
STIX 2.1

Description

The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 does not properly restrict application cookies, which allows remote attackers to read session variables by leveraging a weak setting of the Domain variable.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21654355
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/84968

Scores

EPSS 0.0053
EPSS Percentile 41.8%

Details

CWE
CWE-264
Status published
Products (2)
ibm/lotus_sametime 8.5.2
ibm/lotus_sametime 8.5.2.1
Published Nov 09, 2013
Tracked Since Feb 18, 2026