Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-0354

Опубликовано: 29 авг. 2017
Источник: nvd
CVSS3: 5.5
CVSS2: 6
EPSS Низкий

Описание

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:sametime:8.5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sametime:8.5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sametime:9.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sametime:9.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sametime:9.0.1:*:*:*:*:*:*:*

EPSS

Процентиль: 57%
0.00346
Низкий

5.5 Medium

CVSS3

6 Medium

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 5.5
github
больше 3 лет назад

IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893.

EPSS

Процентиль: 57%
0.00346
Низкий

5.5 Medium

CVSS3

6 Medium

CVSS2

Дефекты

CWE-434