Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-6742

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2013-6742
Last Modified 21 Feb 2014 09:12:36
Published 14 Feb 2014 08:10:48
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2013-6742

Summary

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

Vulnerable Systems

Application

  • Ibm Sametime 8.5.2.0

  • Ibm Sametime 8.5.2.1

  • Ibm Sametime 9.0.0.0

  • Ibm Sametime 9.0.0.1


References

XF - ibm-sametime-ms-cve20136742-autocomplete(89858)

CONFIRM - http://www-01.ibm.com/support/docview.wss?uid=swg21662928


Last Updated: 27 May 2016 11:04:27