First published: Wed Oct 23 2024(Updated: )
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sametime |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30124 is classified as a moderate severity vulnerability due to the potential for unauthorized access through insecure services.
To fix CVE-2024-30124, disable the unused legacy REST service on the HCL Sametime UIM client.
CVE-2024-30124 allows attackers to exploit an insecure, enabled service that can be used to gain unauthorized access.
CVE-2024-30124 affects all versions of HCL Sametime that have the legacy REST service enabled by default.
As a workaround for CVE-2024-30124, you can configure the UIM client to disable the default legacy REST service.