CVE-2023-37540: HCL Sametime Chat is affected by an unimplemented feature in the UI
Sametime Connect desktop chat client includes, but does not use or require, the use of an Eclipse feature called Secure Storage. Using this Eclipse feature to store sensitive data can lead to exposure of that data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37540?
CVE-2023-37540 is classified as a moderate severity vulnerability due to the potential exposure of sensitive data.
How do I fix CVE-2023-37540?
To fix CVE-2023-37540, ensure that the Eclipse Secure Storage feature is properly configured or disabled in the HCL Sametime Chat client.
What data is exposed due to CVE-2023-37540?
CVE-2023-37540 can lead to the exposure of sensitive data due to improper use of the Eclipse Secure Storage feature.
Which versions of HCL Sametime Chat are affected by CVE-2023-37540?
CVE-2023-37540 affects all versions of HCL Sametime Chat that include the Eclipse feature Secure Storage.
What should I do if I suspect a breach related to CVE-2023-37540?
If you suspect a breach related to CVE-2023-37540, immediately review logs for unusual activity and consider notifying affected users.