PT-2014-3924 · Ibm · Ibm Sametime
Published
2014-03-06
·
Updated
2017-08-29
·
CVE-2014-0890
CVSS v2.0
1.9
Low
| Vector | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Sametime versions 8.5.1 through 9.0.0.1
Description
The issue allows local users to obtain sensitive information by reading a log file, specifically cleartext passwords, during Audio/Video chat sessions when a certain
com.ibm.collaboration.realtime.telephony.*.level setting is used.Recommendations
For IBM Sametime versions 8.5.1 through 9.0.0.1, consider disabling the logging feature for Audio/Video chat sessions or adjust the
com.ibm.collaboration.realtime.telephony.*.level setting to prevent cleartext password logging until a fix is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Sametime