CVE-2013-6727

IBM Sametime 8.5.2-8.5.2.1 and 9.0 - Information Disclosure via Unsigned Java Plugins

Title source: llm
STIX 2.1

Description

The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, which allows remote attackers to obtain sensitive information via unspecified vectors.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21662725
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/89282

Scores

EPSS 0.0168
EPSS Percentile 74.6%

Details

CWE
CWE-264
Status published
Products (3)
ibm/sametime 8.5.2.0
ibm/sametime 8.5.2.1
ibm/sametime 9.0.0.0
Published Jan 31, 2014
Tracked Since Feb 18, 2026