Multiple cross-site scripting (XSS) vulnerabilities in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
| Software | From | Fixed in |
|---|---|---|
| ibm / classic_meeting_server | 8.0.1 | 8.0.1.x |
| ibm / lotus_sametime | 8.5.2.1 | 8.5.2.1.x |
| ibm / lotus_sametime | 8.0.1 | 8.0.1.x |
| ibm / lotus_sametime | 8.5 | 8.5.x |
| ibm / lotus_sametime | 8.0 | 8.0.x |
| ibm / classic_meeting_server | 8.5 | 8.5.x |
| ibm / lotus_sametime | 8.0.2 | 8.0.2.x |
| ibm / classic_meeting_server | 8.5.1.2 | 8.5.1.2.x |
| ibm / classic_meeting_server | 7.5.1.2 | 7.5.1.2.x |
| ibm / lotus_sametime | 8.0.1.1 | 8.0.1.1.x |
| ibm / classic_meeting_server | 8.0.2 | 8.0.2.x |
| ibm / lotus_sametime | 8.0.2.1 | 8.0.2.1.x |
| ibm / lotus_sametime | 8.5.2 | 8.5.2.x |
| ibm / lotus_sametime | 7.5.1.2 | 7.5.1.2.x |
| ibm / lotus_sametime | 8.5.1.1 | 8.5.1.1.x |
| ibm / classic_meeting_server | 8.5.2.1 | 8.5.2.1.x |
| ibm / lotus_sametime | 8.5.1 | 8.5.1.x |