CVE-2023-45696

Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:sametime:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:27

Type Values Removed Values Added
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109082 - Vendor Advisory () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109082 - Vendor Advisory
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 4.0

05 Sep 2024, 13:23

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.0
v2 : unknown
v3 : 7.5
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:hcltech:sametime:*:*:*:*:*:*:*:*
First Time Hcltech
Hcltech sametime
Summary
  • (es) Sametime se ve afectado por campos confidenciales con la función de autocompletar habilitada en el cliente de chat web heredado. De forma predeterminada, esto permite que el navegador almacene los datos ingresados por el usuario.
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109082 - () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109082 - Vendor Advisory

10 Feb 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-10 03:15

Updated : 2024-11-21 08:27


NVD link : CVE-2023-45696

Mitre link : CVE-2023-45696

CVE.ORG link : CVE-2023-45696


JSON object : View

Products Affected

hcltech

  • sametime