Vulnerabilities > IBM > Sametime > 9.0.1

DATE CVE VULNERABILITY TITLE RISK
2017-08-29 CVE-2016-0354 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Sametime
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges.
network
ibm CWE-434
6.0
2017-08-29 CVE-2016-2970 Information Exposure vulnerability in IBM Sametime
IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers.
network
low complexity
ibm CWE-200
4.0