CVE-2016-2972

HIGH

IBM Sametime 8.5.2 and 9.0 - Unprotected Credential Storage in Browser Cache

Title source: llm
STIX 2.1

Description

IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100599
VDB Entry, Vendor Advisory x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/113855
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039231
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg22006439

Scores

CVSS v3 7.8
EPSS 0.0034
EPSS Percentile 26.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-255
Status published
Products (10)
ibm/sametime 8.5.2.0
ibm/sametime 8.5.2.1
ibm/sametime 9.0.0.0
ibm/sametime 9.0.0.1
ibm/sametime 9.0.1
IBM/Sametime 8.5.2
IBM/Sametime 8.5.2.1
IBM/Sametime 9.0
IBM/Sametime 9.0.0.1
IBM/Sametime 9.0.1
Published Aug 29, 2017
Tracked Since Feb 18, 2026