HCL Sametime
cpe:2.3:a:hcltech:sametime:*:*:*:*:*:*:*
- <= 12.0.2 FP2
A vulnerability exists in HCL Sametime versions 12.0.2 FP2 and earlier, due to inadequate server-side validation. Although the application includes client-side input checks, these are not applied by the web server. This flaw allows attackers to circumvent restrictions by sending altered HTTP requests directly to the server.
Exploitation of this vulnerability could lead to bypassing of input validation, potentially allowing for further attacks or manipulation of the application.
Users are advised to upgrade to HCL Sametime version 12.0.3. The latest fix releases can be downloaded from My HCLSoftware.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.