Security Bulletin: IBM Sametime log file information disclosure (CVE-2012-3331)

  • 22 Oct, 2012

The default permissions for the IBM Sametime database STLOG.NSF allows anonymous / unauthenticated users to access potentially sensitive information.
Vulnerability Type: Information disclosure
The information bellow is from TN 1613895
CVE ID: CVE-2012-3331
**
DESCRIPTION:**
By default, anonymous / unauthenticated users can access the Sametime Log database (STLOG.NSF).

This database provides a variety of potentially sensitive information including canonical usernames, and client IP addresses.

For example, from the page http://1.2.3.4/stlog.nsf, select the link Community Server Login and Logout Events by User.

Steps to Reproduce Vulnerability: http://1.2.3.4/stlog.nsf

Note that access to the server where the Sametime servers are running should be possible only from within the organization. In addition these servers should not be made HTTP accessible to any machine in the organization.
**
**

Related Posts

Sametime meets Watson

  • 06 Dec, 2016

Bots is a high topic these days and i revisited this kind of application last week. I created a Translation Bot based on this article(http://www.ibm.com/developerworks/lotus/library/ls-STBots1/) from

Sametime meets WatsonRead More

Sametime and IBM Connections integration when you use self certification

  • 20 Oct, 2015

I setup the integration between Sametime Proxy 9.0 and IBM Connections a long time ago. When i access the Connections homepage the sametime widget does not work. After some research i found a solutio

Sametime and IBM Connections integration when you use self certificationRead More

Upgrade the embedded sametime client on Notes 9

  • 24 Sep, 2013

IBM Sametime 9 was launched a few weeks ago.  When i saw this video(http://ibmtvdemo.edgesuite.net/software/lotus/uxid/sametime/ST9wn.mp4) i  do the upgrade of my embedded Sametime client on Notes 9

Upgrade the embedded sametime client on Notes 9Read More