CVE Vulnerabilities

CVE-2014-0890

Published: Mar 06, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration.realtime.telephony.*.level setting is used, logs cleartext passwords during Audio/Video chat sessions, which allows local users to obtain sensitive information by reading a log file.

Affected Software

NameVendorStart VersionEnd Version
SametimeIbm8.5.1.0 (including)8.5.1.0 (including)
SametimeIbm8.5.1.1 (including)8.5.1.1 (including)
SametimeIbm8.5.1.2 (including)8.5.1.2 (including)
SametimeIbm8.5.2.0 (including)8.5.2.0 (including)
SametimeIbm8.5.2.1 (including)8.5.2.1 (including)
SametimeIbm9.0.0.0 (including)9.0.0.0 (including)
SametimeIbm9.0.0.1 (including)9.0.0.1 (including)

References