Vulnerability Details CVE-2013-3978
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwanted caching by a web browser, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.3%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2013-3978
-
cpe:2.3:a:ibm:sametime:8.5.2.0
-
cpe:2.3:a:ibm:sametime:8.5.2.1
-
cpe:2.3:a:ibm:sametime:9.0.0.0
-
cpe:2.3:a:ibm:sametime:9.0.0.1