Sametime
Vendor:
First CVE: Aug 17, 2012 · Active for 13 years
46
Total CVEs
More Total CVEs than 97% of tracked products
9.2
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
4.8
Avg CVSS
Higher Avg CVSS than 6% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sametime over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 17, 2012
13 years ago
Most Recent CVE
Feb 8, 2018
3,088 days ago
CVE Severity & Scoring
Sametime46 CVEs
20%
74%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local3 (6.5%)
Network20 (43.5%)
Unknown23 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (50.0%)
High0 (0.0%)
Unknown23 (50.0%)
User Interaction
None16 (34.8%)
Unknown23 (50.0%)
Required7 (15.2%)
Privileges Required
Low18 (39.1%)
High0 (0.0%)
None5 (10.9%)
Unknown23 (50.0%)
Top CVEs
Signals from CVEs in this product scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-3982MEDIUM The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspecified installation information and technical data via a reque | May 26, 2014 | 5.0 | 28 | NO | YES |
CVE-2013-3975MEDIUM Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to discover user names, full names, and e-mail a | May 26, 2014 | 5.0 | 28 | NO | YES |
CVE-2016-2972HIGH IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-F | Aug 29, 2017 | 7.8 | 24 | NO | NO |
CVE-2013-3977MEDIUM The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge | May 26, 2014 | 4.3 | 24 | NO | YES |
CVE-2016-0356MEDIUM IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease throug | Aug 29, 2017 | 6.5 | 21 | NO | NO |
CVE-2016-2980MEDIUM The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPla | Aug 29, 2017 | 6.3 | 20 | NO | NO |
CVE-2016-2975MEDIUM IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi | Aug 29, 2017 | 5.4 | 20 | NO | NO |
CVE-2016-2965MEDIUM IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicio | Aug 29, 2017 | 6.5 | 20 | NO | NO |
CVE-2013-6742HIGH The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, which makes it easier for remote at | Feb 14, 2014 | 7.5 | 19 | NO | NO |
CVE-2013-3983HIGH The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redirects, which has unspecified impa | Feb 14, 2014 | 7.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (46 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
6.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (46 CVEs).
Media Mentions
Signals from CVEs in this product scope (46 CVEs).
Top CNAs Publishing CVEs For Sametime
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.1 | 22 | 5.1 | 0.8% | 0 | 0 |
| 9.0.0.1 | 36 | 5.0 | 1.9% | 0 | 3 |
| 9.0.0.0 | 39 | 5.0 | 1.8% | 0 | 3 |
| 8.5.2.1 | 46 | 4.8 | 1.7% | 0 | 3 |
| 8.5.2.0 | 45 | 4.8 | 1.8% | 0 | 3 |
| 8.5.2 | 1 | 1.9 | 0.3% | 0 | 0 |
| 8.5.1.2 | 3 | 3.0 | 0.8% | 0 | 0 |
| 8.5.1.1 | 18 | 4.0 | 3.0% | 0 | 3 |
| 8.5.1.0 | 17 | 4.2 | 3.1% | 0 | 3 |
| 8.5.1 | 1 | 1.9 | 0.3% | 0 | 0 |
| 8.5.0.0 | 15 | 4.3 | 3.5% | 0 | 3 |
| 8.0.2.1 | 14 | 4.2 | 3.6% | 0 | 3 |
| 8.0.2.0 | 15 | 4.3 | 3.5% | 0 | 3 |
| 8.0.1.1 | 13 | 4.2 | 3.7% | 0 | 3 |
| 8.0.1.0 | 14 | 4.3 | 3.6% | 0 | 3 |
| 8.0.0.0 | 14 | 4.3 | 3.6% | 0 | 3 |
| 7.5.1.2 | 2 | 4.8 | 1.5% | 0 | 0 |
| 7.5.1.1 | 1 | 5.3 | 1.7% | 0 | 0 |
| 7.5.1.0 | 1 | 5.3 | 1.7% | 0 | 0 |
| 7.5.0.0 | 1 | 5.3 | 1.7% | 0 | 0 |