CVE Vulnerabilities

CVE-2014-0890

Published: Mar 06, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration.realtime.telephony.*.level setting is used, logs cleartext passwords during Audio/Video chat sessions, which allows local users to obtain sensitive information by reading a log file.

Affected Software

Name Vendor Start Version End Version
Sametime Ibm 8.5.1.0 (including) 8.5.1.0 (including)
Sametime Ibm 8.5.1.1 (including) 8.5.1.1 (including)
Sametime Ibm 8.5.1.2 (including) 8.5.1.2 (including)
Sametime Ibm 8.5.2.0 (including) 8.5.2.0 (including)
Sametime Ibm 8.5.2.1 (including) 8.5.2.1 (including)
Sametime Ibm 9.0.0.0 (including) 9.0.0.0 (including)
Sametime Ibm 9.0.0.1 (including) 9.0.0.1 (including)

References