Vulnerability Description
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hcltech | Sametime | >= 11.5, < 12.0.2 |
Related Weaknesses (CWE)
References
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109082Vendor Advisory
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109082Vendor Advisory
FAQ
What is CVE-2023-45696?
CVE-2023-45696 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.
How severe is CVE-2023-45696?
CVE-2023-45696 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-45696?
Check the references section above for vendor advisories and patch information. Affected products include: Hcltech Sametime.