Input validation error in Sametime - CVE-2016-10503

 

Input validation error in Sametime - CVE-2016-10503

Published: August 29, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38394
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10503
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to manipulate data.

IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. IBM X-Force ID: 113803.


Affected software

Sametime

How to mitigate CVE-2016-10503

Install update from vendor's website.


External References

Related Security Bulletins