CVE-2023-50355 – HCL Sametime is impacted by generation of error messages containing sensitive information
https://notcve.org/view.php?id=CVE-2023-50355
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack. • https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0115627 • CWE-209: Generation of Error Message Containing Sensitive Information •
CVE-2024-30124 – HCL Sametime is impacted by insecure services
https://notcve.org/view.php?id=CVE-2024-30124
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously. • https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0115627 • CWE-1188: Initialization of a Resource with an Insecure Default •
CVE-2024-30122 – HCL Sametime is impacted by misconfigured security related HTTP headers
https://notcve.org/view.php?id=CVE-2024-30122
HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers. • https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0115627 • CWE-922: Insecure Storage of Sensitive Information •