Next vulnerability: Sametime 3.1 - 7.0 this time

by Thomas Bahn,
assono GmbH, Standort Kiel,


There is another recently published vulnerability, IBM Lotus Sametime this time. Versions 3.1, 6.5.1 and 7.0 are affected, but not 7.5:

The affectect JNILoader ActiveX control
is not used in Sametime 7.5 anymore, thus this version is not affected.
A hotfix for Sametime 7.0 exists.


But the easiest workaround is not to
use Internet Explorer  wink.gif


More details:

IBM Lotus Sametime JNILoader Vulnerability

iDefense contacted IBM® Lotus® to report a potential vulnerability with the JNILoader ActiveX control used by the IBM Lotus Sametime® Web Conferencing server.

The iDefense advisory can be accessed from the following link: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=495

The JNILoader ActiveX control was introduced in early versions of the Sametime web conferencing server in order to prevent crashes caused by the length of time it took to uninitialize the Sametime audio/video DLLs when closing the browser. The JNILoader control was scriptable to allow for DLL version changes between Sametime server releases. The primary function of this ActiveX control was to load/unload native Sametime DLLs, however, the control can be re-used on non-Sametime pages such that the scriptable "loadLibrary()" function has the potential to be exploited to load malicious code on the local workstation. This functionality was replaced in Sametime 7.5 with a 100% Java-based, and non-scriptable solution which could be used with all browsers. In controlled environments, there is no risk with Sametime servers. The risk is when the Sametime related ActiveX control is used on non-Sametime web pages.

Technical article Sametime Security

Sie haben Fragen zu diesem Artikel? Kontaktieren Sie uns gerne: blog@assono.de

Do you want an individual solution? Contact us

More interesting entries

Any questions? Contact us.

If you want to know more about our offers, you can contact us at any time. There are several ways to contact us for a non-binding first consultation.

We don’t sell your data. 100% guaranteed. See: Privacy Policy
assono GmbH

Location Kiel (headquarters)
assono GmbH
Lise-Meitner-Straße 1–7
24223 Schwentinental

Location Hamburg
assono GmbH
Bornkampsweg 58
22761 Hamburg

Phone numbers:
Human resources department: +49 4307 900 407
Marketing department: +49 4307 900 402

E-Mail adresses:
contact@assono.de
bewerbung@assono.de