HCL Sametime Server-Side Validation Vulnerability

Vulnerability

A vulnerability exists in HCL Sametime versions 12.0.2 FP2 and earlier, due to inadequate server-side validation. Although the application includes client-side input checks, these are not applied by the web server. This flaw allows attackers to circumvent restrictions by sending altered HTTP requests directly to the server.

Impact

Exploitation of this vulnerability could lead to bypassing of input validation, potentially allowing for further attacks or manipulation of the application.

Remediation

Users are advised to upgrade to HCL Sametime version 12.0.3. The latest fix releases can be downloaded from My HCLSoftware.

Added: Mar 17, 2026, 12:19 PM
Updated: Mar 17, 2026, 12:19 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.6
exploitability
4.9
remediation
7.7
relevance
4.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.