CVE-2021-27772 - CVE House
Back to Database
Status published High CVE-2021-27772

HCL Sametime is vulnerable to an information disclosure

Vulnerability Description

Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it. This could lead to information leakage where confidential information discussed in private groups is read by other users without the users knowledge.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-27772

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

HCL Software

View all reports →

Affected Software

Sametime
Vulnerable Versions:
11.6

Timeline

Official Publish: May 12th, 2022
Last Modified: September 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Weaknesses (CWE)