CVE-2025-31966

HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:sametime:*:*:*:*:*:-:*:*

History

31 Mar 2026, 21:06

Type Values Removed Values Added
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124722 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124722 - Vendor Advisory
Summary
  • (es) HCL Sametime es vulnerable a una validación rota del lado del servidor. Aunque la aplicación realiza comprobaciones de entrada del lado del cliente, estas no son aplicadas por el servidor web. Un atacante puede eludir estas restricciones enviando solicitudes HTTP manipuladas directamente al servidor.
CPE cpe:2.3:a:hcltech:sametime:*:*:*:*:*:-:*:*
First Time Hcltech
Hcltech sametime

17 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 12:16

Updated : 2026-03-31 21:06


NVD link : CVE-2025-31966

Mitre link : CVE-2025-31966

CVE.ORG link : CVE-2025-31966


JSON object : View

Products Affected

hcltech

  • sametime
CWE
CWE-20

Improper Input Validation