CVE-2024-30124

MEDIUM

HCL Sametime - Info Disclosure

Title source: llm
STIX 2.1

Description

HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.

Scores

CVSS v3 4.0
EPSS 0.0008
EPSS Percentile 22.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1188
Status published
Products (2)
hcltech/sametime 12.0.2
hcltech/sametime < 12.0.2
Published Oct 23, 2024
Tracked Since Feb 18, 2026