CVE Vulnerabilities

CVE-2024-30124

Initialization of a Resource with an Insecure Default

Published: Oct 23, 2024 | Modified: Jan 08, 2026
CVSS 3.x
4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.

Weakness

The product initializes or sets a resource with a default that is intended to be changed by the product’s installer, administrator, or maintainer, but the default is not secure.

Affected Software

NameVendorStart VersionEnd Version
SametimeHcltech*12.0.2 (excluding)
SametimeHcltech12.0.2 (including)12.0.2 (including)

References