Home

Description

HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.

PUBLISHED Reserved 2025-04-01 | Published 2026-03-17 | Updated 2026-03-17 | Assigner HCL




LOW: 2.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-20 Improper input validation

Product status

Default status
unaffected

Version 2.0.2 FP2 and older
affected

References

support.hcl-software.com/...rticle&sysparm_article=KB0124722

cve.org (CVE-2025-31966)

nvd.nist.gov (CVE-2025-31966)

Download JSON