CVE Vulnerabilities

CVE-2023-37540

Insecure Storage of Sensitive Information

Published: Feb 23, 2024 | Modified: Jan 09, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Sametime Connect desktop chat client includes, but does not use or require, the use of an Eclipse feature called Secure Storage. Using this Eclipse feature to store sensitive data can lead to exposure of that data.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Sametime Hcltech 11.5 (including) 12.0.2 (excluding)

References