CVE-2025-32000: Insufficient Input Sanitization is addressed in HCL Sametime 12.0.4. It is recommended to upgrade to the latest version.
HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly trusted without sufficient sanitization, malicious actors can leverage this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HCL Sametimeto a version that resolves this vulnerability.Fixed in 12.0.4
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability is remotely reachable and requires no privileges, but it does require user interaction. The available data does not specify what form that interaction takes.
What is the potential impact if exploitation succeeds?
The reported impact is limited to confidentiality, with no stated integrity or availability impact. The severity is rated medium with a CVSS score of 4.3.
Which version addresses the issue?
HCL Sametime 12.0.4 addresses the insufficient input sanitization vulnerability. Upgrading to the latest version is recommended.