PT-2017-8275 · Ibm · Ibm Sametime Meeting Server
Published
2017-08-29
·
Updated
2017-09-07
·
CVE-2016-2965
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Sametime Meeting Server versions 8.5.2 through 9.0
Description
The issue is caused by improper validation of user-supplied input, allowing for cross-site request forgery. A remote attacker could force a user to log out of Sametime by persuading the user to visit a malicious link.
Recommendations
For versions 8.5.2 through 9.0, update to a version that includes proper validation of user-supplied input to prevent cross-site request forgery attacks.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Sametime Meeting Server