VYPR
Medium severity4.0NVD Advisory· Published Oct 23, 2024· Updated Jun 17, 2026

CVE-2024-30124

CVE-2024-30124

Description

HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.

Affected products

4
  • HCLTech/Sametime2 versions
    cpe:2.3:a:hcltech:sametime:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:hcltech:sametime:*:*:*:*:*:*:*:*range: <12.0.2
    • cpe:2.3:a:hcltech:sametime:12.0.2:-:*:*:*:*:*:*
  • HCL Software/Sametimellm-create2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=12.0.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.