CVE-2025-31966Disclosure(hcltech / sametime)

LOWCVSS 2.7 · LOW

Signal is active with 8 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sametime

Threat summary

  • 8 mentions across 1 observed day

What's happening

  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Disclosures: 1 classified signal
  • 8 total mentions across 1 day

Affected systems

Vendors
Products
sametime

Deep dive

Activity timeline8 mentions / 1d
02468Mentions · 2026-03-17: 8Technical Details · 2026-03-17: 703-17
Signal classification3 categories
Disclosure
450.0%
General
337.5%
Disclosures
112.5%
Referenced assets8 URLs
Full discourse8 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-31966 HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An att… https://www.cve.org/CVERecord?id=CVE-2025-31966

    Post summary

    The text reports CVE-2025-31966 as a broken server‑side validation issue in HCL Sametime, providing limited technical detail but nothing about PoC, exploitation, or patching.

    00000154
    56.8K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-31966 📊 Severity: 2.7 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-31966 #CVE-2025-31966 #CVE #Low  #CyberSecurity #InfoSec https://t.co/bsGSORDEAx

    Post summary

    The tweet announces CVE-2025-31966 with a low severity score and references the NVD entry, but provides no PoC, exploit, patch, or detailed technical information.

    00000105
    101 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-31966 - Boolean-Based SQL Injection in Multiple Unica Components Intel Report: https://ift.tt/6mUKrhz

    Post summary

    A new Boolean‑based SQL injection vulnerability (CVE‑2025‑31966) has been disclosed across multiple Unica components, with technical details available in the linked Intel Report.

    00000113
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosures

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-31966 - Boolean-Based SQL Injection in Multiple Unica Components Intel Report: https://ift.tt/LXs3NQO

    Post summary

    The alert announces CVE-2025-31966 as a Boolean‑based SQL injection affecting multiple Unica components, directing readers to an Intel report for additional details.

    00000134
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-31966 - Boolean-Based SQL Injection in Multiple Unica Components Intel Report: https://ift.tt/4y0uA9O

    Post summary

    The alert announces a Boolean‑Based SQL Injection vulnerability (CVE‑2025‑31966) affecting multiple Unica components, but offers no PoC, exploit, or patch details.

    0000099
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-31966 - Boolean-Based SQL Injection in Multiple Unica Components Intel Report: https://ift.tt/6fw4ljZ

    Post summary

    The alert references CVE-2025-31966, highlighting a Boolean-based SQL injection in Unica components, but provides no PoC, exploit details, active exploitation evidence, or mitigation information.

    0000096
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-31966 - Boolean-Based SQL Injection in Multiple Unica Components Intel Report: https://ift.tt/szIWFOJ

    Post summary

    A threat alert references CVE-2025-31966, a Boolean‑based SQL injection targeting multiple Unica components, providing only a brief description and a link to an Intel report without details on PoC, exploit, patch, or active exploitation.

    0000080
    336 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-31966 HCL Sametime Server-Side Validation Bypass Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-31966

    Post summary

    The post lists the CVE identifier CVE-2025-31966, a brief description of a server-side validation bypass in HCL Sametime, and provides a link for additional details.

    0000073
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphcltechsametime---

Explore more