HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.
| Software | From | Fixed in |
|---|---|---|
| hcltech / sametime | - | 12.0.2 |
| hcltech / sametime | 12.0.2 | 12.0.2.x |