CVE-2024-30122

MEDIUM

HCL Sametime - Info Disclosure

Title source: llm
STIX 2.1

Description

HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.

Scores

CVSS v3 5.8
EPSS 0.0016
EPSS Percentile 36.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-922
Status published
Products (2)
hcltech/sametime 12.0.2
hcltech/sametime < 12.0.2
Published Oct 23, 2024
Tracked Since Feb 18, 2026