CVE-2025-32000
Received Received - Intake

Insufficient Input Sanitization in HCL Sametime

Vulnerability report for CVE-2025-32000, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: HCL Software

Description

HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly trusted without sufficient sanitization, malicious actors can leverage this vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl sametime *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HCL Sametime is vulnerable to insufficient input sanitization. The application does not properly sanitize user input, allowing malicious actors to exploit this weakness. This could lead to unauthorized actions or data exposure depending on the context of the input.

Impact Analysis

This vulnerability may allow attackers to inject malicious input that could be processed by the application. This could result in data leaks, unauthorized access, or other unintended behavior if the input is used in sensitive operations.

Compliance Impact

Insufficient input sanitization can lead to data breaches or unauthorized data exposure, violating compliance requirements such as GDPR or HIPAA. Organizations may face penalties or legal consequences if this vulnerability is exploited due to inadequate data protection measures.

Mitigation Strategies

Apply the latest security patches or updates provided by HCL for Sametime Connect desktop chat client as referenced in the vendor advisory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-32000. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart