PT-2026-25894 · Hcl · Sametime

Published

2026-03-17

·

Updated

2026-03-17

·

CVE-2025-31966

CVSS v3.1
2.7
VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-31966

Affected Products

Sametime