← Vulnerability feed

Vulnerability record · CVE-2016-2980 · published 29 August 2017

CVE-2016-2980: Ibm sametime injection vulnerability

Ibm · Sametime

The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Force ID: 113993.

6.3 CVSS 3.0 Medium EPSS 1.0% · top 38.4% CWE-74 · Injection
6.3CVSS 3.0 base score, v2 6.8
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Force ID: 113993.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-2980 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2016-2972Ibm sametime vulnerabilityIBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be ac…EPSS 0.35%7.5CVE-2013-3983Ibm sametime improper input validation vulnerabilityThe Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redire…EPSS 1.1%7.5CVE-2013-6742Ibm sametime permissions and access controls vulnerabilityThe Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, whic…EPSS 1.3%6.8CVE-2013-3988Ibm sametime improper input validation vulnerabilityThe Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to conduct clickjacking attacks via unspecif…EPSS 1.2%6.5CVE-2016-0355Ibm sametime cross-site request forgery vulnerabilityIBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the…EPSS 0.71%6.5CVE-2016-0356Ibm sametime cross-site request forgery vulnerabilityIBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the…EPSS 0.71%6.5CVE-2016-2965Ibm sametime cross-site request forgery vulnerabilityIBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persu…EPSS 0.80%5.5CVE-2016-0354Ibm sametime unrestricted file upload vulnerabilityIBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that co…EPSS 0.77%

Source: NIST National Vulnerability Database (record CVE-2016-2980), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.