CVE-2023-45718: HCL Sametime is impacted by a failure to invalidate sessions
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45718?
CVE-2023-45718 is rated as high severity due to the potential for unauthorized session access.
How do I fix CVE-2023-45718?
To fix CVE-2023-45718, update your HCL Sametime software to a version that addresses this session management vulnerability.
What are the risks associated with CVE-2023-45718?
The risks include the possibility of session hijacking, allowing attackers to impersonate legitimate users.
Which versions of HCL Sametime are affected by CVE-2023-45718?
CVE-2023-45718 affects HCL Sametime versions between 11.5 and 12.0.2.
Is there a workaround for CVE-2023-45718 before applying a fix?
A temporary workaround for CVE-2023-45718 is to ensure users log out completely to invalidate sessions.