CVE-2013-3978: IBM Sametime

Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwanted caching by a web browser, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.

Affected products

  • IBM Sametime: version 8.5.2.0 only; version 8.5.2.1 only; version 9.0.0.0 only; version 9.0.0.1 only

Published 2014-02-14. Last modified 2026-06-16.