CVE-2025-31966
LOWCVSS 2.7/10EPSS 0.19%
Last modified
CVE-2025-31966 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hcltech | Sametime | < 12.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-31966?
HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.
How severe is CVE-2025-31966?
CVE-2025-31966 has a CVSS score of 2.7/10 (LOW severity). The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.
How do I fix CVE-2025-31966?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-31960HCL BigFix Service Management (SM) is vulnerable to informat…5.3
- CVE-2025-31961HCL Connections contains a broken access control vulnerabili…4.6
- CVE-2025-31962Insufficient session expiration in the Web UI authentication…4.3
- CVE-2025-31963Improper authentication and missing CSRF protection in the l…3.3
- CVE-2025-31964Improper service binding configuration in internal service c…4.9
- CVE-2025-31965Improper access restrictions in HCL BigFix Remote Control Se…8.2
- CVE-2025-31969HCL Unica Platform is impacted by misconfigured Content Secu…6.1
- CVE-2025-3197Versions of the package expand-object from 0.0.0 are vulnera…7.3
- CVE-2025-31970HCL DFXAnalytics is affected by an Insecure Security Header …6.1
- CVE-2025-31971AIML Solutions for HCL SX is vulnerable to a URL validation …5.1
- CVE-2025-31972HCL BigFix SM is affected by a Sensitive Information Exposur…6.5
- CVE-2025-31973HCL BigFix Service Management (SM) is susceptible to a Conf…9.8
Are you affected by CVE-2025-31966?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
