| Vulnerability Name: | CVE-2013-3983 (CCN-84966) | ||||||||
| Assigned: | 2013-06-07 | ||||||||
| Published: | 2014-02-06 | ||||||||
| Updated: | 2017-08-29 | ||||||||
| Summary: | The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redirects, which has unspecified impact and remote attack vectors. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-20 | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: MITRE Type: CNA CVE-2013-3983 Source: CCN Type: IBM Security Bulletin 1662928 Several Security Fixes to IBM Sametime Meeting Server. (CVE-2013-3983, CVE-2013-3978, CVE-2013-3988, CVE-2013-6742, CVE-2013-6743) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21662928 Source: CCN Type: BID-65610 IBM Sametime Meeting Server CVE-2013-3983 Open Redirection Vulnerability Source: XF Type: UNKNOWN ibm-sametime-cve20133983-url-redirect(84966) Source: XF Type: UNKNOWN ibm-sametime-ms-cve20133983-redirect(84966) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||