CVE-2025-31966: Hcltech Sametime
Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.
HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.
Affected products
- Hcltech Sametime: before 12.0.3 (fixed in 12.0.3)
Published 2026-03-17. Last modified 2026-06-17.