CVE-2024-30124

HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.
Configurations

No configuration.

History

29 Oct 2024, 15:35

Type Values Removed Values Added
CWE CWE-1188

25 Oct 2024, 12:56

Type Values Removed Values Added
Summary
  • (es) HCL Sametime se ve afectado por servicios inseguros que se utilizan en el cliente UIM de forma predeterminada. Se habilitó un servicio REST heredado sin usar de forma predeterminada mediante el protocolo HTTP. Un atacante podría usar este endpoint de servicio de forma maliciosa.

23 Oct 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-23 16:15

Updated : 2024-10-29 15:35


NVD link : CVE-2024-30124

Mitre link : CVE-2024-30124

CVE.ORG link : CVE-2024-30124


JSON object : View

Products Affected

No product.

CWE
CWE-1188

Insecure Default Initialization of Resource