| Vulnerability Name: | CVE-2016-2974 (CCN-113934) | ||||||||||||
| Assigned: | 2016-03-09 | ||||||||||||
| Published: | 2017-08-25 | ||||||||||||
| Updated: | 2017-09-01 | ||||||||||||
| Summary: | IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934. | ||||||||||||
| CVSS v3 Severity: | 3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-200 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-2974 Source: CCN Type: IBM Security Bulletin 2006444 (Sametime) Security vulnerabilities in IBM Sametime Connect client (CVE-2016-0243, CVE-2016-2974) Source: CONFIRM Type: Patch, Vendor Advisory http://www.ibm.com/support/docview.wss?uid=swg22006444 Source: BID Type: Third Party Advisory, VDB Entry 100528 Source: CCN Type: BID-100528 IBM Sametime Connect Client CVE-2016-2974 Information Disclosure Vulnerability Source: MISC Type: VDB Entry, Vendor Advisory https://exchange.xforce.ibmcloud.com/vulnerabilities/113934 Source: XF Type: UNKNOWN ibm-sametime-cve20162974-info-disc(113934) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||