CVE-2023-37540: HCL Sametime Chat is affected by an unimplemented feature in the UI

Published Feb 23, 2024
·
Updated

Sametime Connect desktop chat client includes, but does not use or require, the use of an Eclipse feature called Secure Storage. Using this Eclipse feature to store sensitive data can lead to exposure of that data.

Affected Software

2 affected components
HCL Sametime Chat
hcltech Sametime>=11.5<12.0.2

Event History

Feb 23, 2024
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
DescriptionSeverity
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-37540?

CVE-2023-37540 is classified as a moderate severity vulnerability due to the potential exposure of sensitive data.

2

How do I fix CVE-2023-37540?

To fix CVE-2023-37540, ensure that the Eclipse Secure Storage feature is properly configured or disabled in the HCL Sametime Chat client.

3

What data is exposed due to CVE-2023-37540?

CVE-2023-37540 can lead to the exposure of sensitive data due to improper use of the Eclipse Secure Storage feature.

4

Which versions of HCL Sametime Chat are affected by CVE-2023-37540?

CVE-2023-37540 affects all versions of HCL Sametime Chat that include the Eclipse feature Secure Storage.

5

What should I do if I suspect a breach related to CVE-2023-37540?

If you suspect a breach related to CVE-2023-37540, immediately review logs for unusual activity and consider notifying affected users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203