6.1

CVE-2023-45698

HCL Sametime is impacted by clickjacking

Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Sametime Chat And Meetings Version 11.6 Update if1
Hcltech ≫ Sametime Chat And Meetings Version 12.0 Update fp1
Hcltech ≫ Sametime Chat And Meetings Version 12.0.1
Hcltech ≫ Sametime Chat And Meetings Version 12.0.1 Update fp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.233
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
psirt@hcl.com 4.8 1.2 3.6
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-1021 Improper Restriction of Rendered UI Layers or Frames

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109082
Vendor Advisory