CVE-2024-30124: Hcltech Sametime
Medium severity, CVSS 4.0. EPSS: 0.2% chance of exploitation in the next 30 days.
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.
Affected products
- Hcltech Sametime: before 12.0.2 (fixed in 12.0.2); version 12.0.2 only
Published 2024-10-23. Last modified 2026-06-17.