PT-2014-3924 · Ibm · Ibm Sametime
Publicado
2014-03-06
·
Atualizado
2017-08-29
·
CVE-2014-0890
CVSS v2.0
1.9
Baixa
| Vetor | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sametime versions 8.5.1 through 9.0.0.1
Description
The issue allows local users to obtain sensitive information by reading a log file, specifically cleartext passwords, during Audio/Video chat sessions when a certain
com.ibm.collaboration.realtime.telephony.*.level setting is used.Recommendations
For IBM Sametime versions 8.5.1 through 9.0.0.1, consider disabling the logging feature for Audio/Video chat sessions or adjust the
com.ibm.collaboration.realtime.telephony.*.level setting to prevent cleartext password logging until a fix is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Sametime