CVE-2025-31966
EUVD-2025-20877717.03.2026, 12:16
HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hcltech | sametime | 𝑥 < 12.0.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration