CVE-2025-31966

LOW

Boolean-Based SQL Injection in Multiple Unica Components

Title source: cna
STIX 2.1

Description

HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.

Scores

CVSS v3 2.7
EPSS 0.0006
EPSS Percentile 19.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
HCL/Sametime Version 2.0.2 FP2 and older
hcltech/sametime < 12.0.3
Published Mar 17, 2026
Tracked Since Mar 17, 2026