PT-2022-26437 · Ibm · Sametime

Published

2022-11-30

·

Updated

2022-12-15

·

CVE-2022-42446

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sametime versions 12 and later
Description The issue allows anonymous users to browse the User Directory and potentially create chats with internal users after logging in.
Recommendations For Sametime version 12 and later, consider disabling anonymous user access to restrict the ability to browse the User Directory and create chats with internal users.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2022-42446

Affected Products

Sametime