Lucene search

K

Hcl Sametime Security Vulnerabilities

cve
cve

CVE-2023-37540

Sametime Connect desktop chat client includes, but does not use or require, the use of an Eclipse feature called Secure Storage. Using this Eclipse feature to store sensitive data can lead to exposure of that...

3.9CVSS

4.3AI Score

0.0004EPSS

2024-02-23 07:15 AM
53
cve
cve

CVE-2023-45698

Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking...

4.8CVSS

5.1AI Score

0.0004EPSS

2024-02-10 04:15 AM
16
cve
cve

CVE-2023-45696

Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the...

4CVSS

4.3AI Score

0.0004EPSS

2024-02-10 03:15 AM
13
cve
cve

CVE-2023-45718

Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their...

3.9CVSS

4.3AI Score

0.0004EPSS

2024-02-09 10:15 PM
15
cve
cve

CVE-2023-45716

Sametime is impacted by sensitive information passed in...

4.1CVSS

4.4AI Score

0.0004EPSS

2024-02-09 10:15 PM
16
cve
cve

CVE-2023-50349

Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the...

8.8CVSS

8.7AI Score

0.001EPSS

2024-02-09 09:15 PM
12
cve
cve

CVE-2022-42446

Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal...

6.5CVSS

6.4AI Score

0.001EPSS

2022-12-12 01:15 PM
40
cve
cve

CVE-2021-27760

An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript...

5.5CVSS

5.8AI Score

0.001EPSS

2022-05-06 06:15 PM
47
4
cve
cve

CVE-2021-27753

"Sametime Android PathTraversal...

5.5CVSS

5.5AI Score

0.0004EPSS

2022-02-21 06:15 PM
65
cve
cve

CVE-2021-27755

"Sametime Android potential path traversal vulnerability when using File...

5.5CVSS

5.5AI Score

0.0004EPSS

2022-02-21 06:15 PM
63