CVE-2013-3985
low
CVSS v3
—
CVSS v2
2.9
VIR risk
2.9
Description
The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 does not properly restrict application cookies, which allows remote attackers to read session variables by leveraging a weak setting of the Domain variable.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21654355
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | lotus_sametime | 8.5.2 | |
| ibm | lotus_sametime | 8.5.2.1 | |
References
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.