4.3
CVSSv2

CVE-2014-0906

Published: 26/05/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Meeting Server in IBM Sametime 8.x up to and including 8.5.2.1 and 9.x up to and including 9.0.0.1 does not check whether a session cookie is current, which allows remote malicious users to conduct user-search actions by leveraging possession of a (1) expired or (2) invalidated cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm sametime 9.0.0.0

ibm sametime 8.5.2.1

ibm sametime 8.0.1.1

ibm sametime 8.0.1.0

ibm sametime 8.5.1.1

ibm sametime 8.5.2.0

ibm sametime 8.0.0.0

ibm sametime 8.0.2.1

ibm sametime 8.0.2.0

ibm sametime 8.5.1.0

ibm sametime 8.5.0.0