CVE-2011-1370

The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authentication requirement, which allows remote attackers to read the configuration settings by examining a response message.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:lotus_sametime:7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_sametime:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_sametime:7.5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_sametime:7.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_sametime:7.5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_sametime:7.5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_sametime:8.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_sametime:8.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_sametime:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_sametime:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_sametime:8.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_sametime:8.5.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2011-10-29 10:55

Updated : 2023-12-10 11:03


NVD link : CVE-2011-1370

Mitre link : CVE-2011-1370

CVE.ORG link : CVE-2011-1370


JSON object : View

Products Affected

ibm

  • lotus_sametime
CWE
CWE-16

Configuration