CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.2. It may lead to a denial-of-service condition.
CVE
CVE-2021-27771
Severity
HIGH
CVSS
8.2
EPSS
0.70%
Original NVD Description
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.
Related CVEs
Other vulnerabilities affecting the same vendor(s)