VulnerabilityModified
CVE-2011-1106
Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to inject arbitrary web script or HTML via the authReasonCode parameter in an OpenDatabase action.
MEDIUM 4.3EPSS 1.48%
Does this matter?
Lower severity and a low EPSS score (1.48%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to inject arbitrary web script or HTML via the authReasonCode parameter in an OpenDatabase action.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.48% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/lotus sametime
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2011-02/0217.htmlExploit
- http://secunia.com/advisories/43430Vendor Advisory
- http://www.securityfocus.com/bid/46481Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65555
- http://archives.neohapsis.com/archives/bugtraq/2011-02/0217.htmlExploit
- http://secunia.com/advisories/43430Vendor Advisory
- http://www.securityfocus.com/bid/46481Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65555
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.