Unrated severityNVD Advisory· Published Feb 14, 2014· Updated Jun 16, 2026
CVE-2013-3983
CVE-2013-3983
Description
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redirects, which has unspecified impact and remote attack vectors.
Affected products
5cpe:2.3:a:ibm:sametime:8.5.2.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:ibm:sametime:8.5.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:sametime:8.5.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:sametime:9.0.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:sametime:9.0.0.1:*:*:*:*:*:*:*
- (no CPE)range: >= 8.5.2, <= 8.5.2.1, >= 9.0, <= 9.0.0.1
Patches
Vulnerability mechanics
References
2- www-01.ibm.com/support/docview.wssnvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/84966nvd
News mentions
0No linked articles in our index yet.