| Vulnerability Name: | CVE-2013-3984 (CCN-84967) | ||||||||
| Assigned: | 2013-06-07 | ||||||||
| Published: | 2014-05-21 | ||||||||
| Updated: | 2017-08-29 | ||||||||
| Summary: | The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | ||||||||
| CVSS v3 Severity: | 4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 2.9 Low (CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N) 2.1 Low (Temporal CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
2.1 Low (CCN Temporal CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-200 | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2013-3984 Source: MITRE Type: CNA CVE-2014-3867 Source: CCN Type: IBM Security Bulletin 1671201 Various Meeting Server Security Fixes Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21671201 Source: CCN Type: BID-67631 IBM Sametime Meeting Server CVE-2013-3984 Session Cookie Security Bypass Vulnerability Source: CCN Type: BID-67659 IBM Sametime Meeting Server CVE-2014-3867 Session Cookie Security Bypass Vulnerability Source: XF Type: UNKNOWN ibm-sametime-cve20133984-info-disclosure(84967) Source: XF Type: UNKNOWN sametime-cve20133984-cookie-flags(84967) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||