CVE-2021-27771: HCL Sametime is susceptible a file transfer service vulnerability
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27771?
CVE-2021-27771 has a moderate severity rating due to its potential for arbitrary file upload or deletion of directories.
How do I fix CVE-2021-27771?
To fix CVE-2021-27771, update HCL Sametime to version 11.6 or later that includes the necessary patches.
What type of attack is CVE-2021-27771 associated with?
CVE-2021-27771 is associated with arbitrary file upload attacks which can lead to denial of service.
Which software versions are affected by CVE-2021-27771?
CVE-2021-27771 affects HCL Sametime version 11.6.
Can CVE-2021-27771 impact system security?
Yes, CVE-2021-27771 can compromise system security by allowing unauthorized file operations.