Home/Product/ibm sametime
Product

ibm sametime

64 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-31966
< 12.0.3
HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are no
2.7LOW
CVE-2026-21791
< 12.0.22
HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in application logs
3.3LOW
CVE-2026-21786
< 12.0.26
HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and
3.3LOW
CVE-2023-50355
< 12.0.2
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch a
3.6LOW
CVE-2024-30124
< 12.0.2
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by de
4.0MEDIUM
CVE-2024-30122
< 12.0.2
HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on
5.8MEDIUM
CVE-2023-37540
>= 11.5 and < 12.0.2
Sametime Connect desktop chat client includes, but does not use or require, the use of an Eclipse feature called Secure Storage. U
3.9LOW
CVE-2023-45696
>= 11.5 and < 12.0.2
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user ent
4.0MEDIUM
CVE-2023-45718
>= 11.5 and < 12.0.2
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent mann
3.9LOW
CVE-2023-45716
< 12.0.2
Sametime is impacted by sensitive information passed in URL.
1.7LOW
CVE-2023-50349
< 12.0.2
Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can a
5.9MEDIUM
CVE-2022-42446
all versions
Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to b
6.5MEDIUM
CVE-2021-27773
all versions
This vulnerability allows users to execute a clickjacking attack in the meeting's chat.
4.2MEDIUM
CVE-2021-27772
all versions
Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able
7.1HIGH
CVE-2021-27771
all versions
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When intera
8.2HIGH
CVE-2021-27770
all versions
The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested b
6.8MEDIUM
CVE-2021-27769
all versions
Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This infor
5.3MEDIUM
CVE-2019-10297
all versions
Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be vi
8.8HIGH
CVE-2012-3331
all versions
IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.
5.3MEDIUM
CVE-2016-2980
all versions
The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exp
6.3MEDIUM
CVE-2016-2978
all versions
IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to
3.3LOW
CVE-2016-2976
all versions
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared sensitive information by view
4.3MEDIUM
CVE-2016-2975
all versions
IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
5.4MEDIUM
CVE-2016-2974
all versions
IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information
3.3LOW
CVE-2016-2967
all versions
IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
5.4MEDIUM
CVE-2016-2966
all versions
IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing the meeting room id. IBM X-For
4.3MEDIUM
CVE-2016-2964
all versions
IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too detailed and may reveal detail
5.3MEDIUM
CVE-2016-0358
all versions
IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings tha
4.3MEDIUM
CVE-2016-2979
all versions
IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar
5.4MEDIUM
CVE-2016-2977
all versions
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in the meeting. IBM X-Force ID:
4.3MEDIUM
CVE-2016-2973
all versions
IBM Sametime Media Services 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar
5.4MEDIUM
CVE-2016-2972
all versions
IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browse
7.8HIGH
CVE-2016-2971
all versions
IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker
5.3MEDIUM
CVE-2016-2969
all versions
IBM Sametime Meeting Server 8.5.2 and 9.0 may send replies that contain emails of people that should not be in these messages. IBM
4.3MEDIUM
CVE-2016-2965
all versions
IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-suppl
6.5MEDIUM
CVE-2016-2959
all versions
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges. IBM X-Forc
4.3MEDIUM
CVE-2016-10503
all versions
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all ha
4.3MEDIUM
CVE-2016-0356
all versions
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting
6.5MEDIUM
CVE-2016-0355
all versions
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting
6.5MEDIUM
CVE-2016-0354
all versions
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime me
5.5MEDIUM
CVE-2016-2970
all versions
IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the a
4.3MEDIUM
CVE-2014-4748
all versions
Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows remote attackers
CVE-2014-4747
all versions
The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting passwor
CVE-2014-3867
all versions
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie
CVE-2014-3014
all versions
Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows
CVE-2014-0906
all versions
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not check whether a session cookie is current,
CVE-2013-3984
all versions
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not set the secure flag for an unspecified coo
CVE-2013-3982
all versions
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspecified insta
CVE-2013-3981
all versions
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to download avatar photos o
CVE-2013-3980
all versions
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to cause a denial of servic
CVE-2013-3977
all versions
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting
CVE-2013-3975
all versions
Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attacker
CVE-2013-3046
all versions
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not send the HSTS Strict-Transport-Security he
CVE-2014-0890
all versions
The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration
CVE-2013-6743
all versions
Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allow
CVE-2013-6742
all versions
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a p
CVE-2013-3988
all versions
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to conduct clickjacking a
CVE-2013-3983
all versions
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before u
CVE-2013-3978
all versions
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response heade
CVE-2013-6727
all versions
The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, whic
CVE-2013-6733
all versions
Cross-site scripting (XSS) vulnerability in the Web Application in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.
CVE-2013-0534
all versions
The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, and 8.5.2.1, as used in the Lotus Notes client and separately,
CVE-2013-0553
all versions
The client implementation in IBM Sametime 8.5.1 through 8.5.2.1, as used in Sametime Connect client, Sametime Advanced Connect cli
CVE-2012-3308
all versions
Cross-site scripting (XSS) vulnerability in IBM Sametime 8.0.2 through 8.5.2.1 allows remote attackers to inject arbitrary web scr
threatengine.sh