CVE-2013-3985: IBM Lotus Sametime
Low severity, CVSS 2.9. EPSS: 0.5% chance of exploitation in the next 30 days.
The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 does not properly restrict application cookies, which allows remote attackers to read session variables by leveraging a weak setting of the Domain variable.
Affected products
- IBM Lotus Sametime: version 8.5.2 only; version 8.5.2.1 only
Published 2013-11-09. Last modified 2026-06-16.