PT-2024-2332 · Hcl · Hcl Sametime Chat/Meetings

Published

2024-02-09

·

Updated

2024-09-05

·

CVE-2023-45696

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HCL Sametime Chat and Meetings (affected versions not specified)
Description The issue is related to the lack of protection for sensitive data in the HCL Sametime Chat and Meetings software. It is mentioned that sensitive fields have autocomplete enabled in the Legacy web chat client, which by default allows user-entered data to be stored by the browser. This could potentially allow an attacker to disclose protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-02275
CVE-2023-45696

Affected Products

Hcl Sametime Chat/Meetings