Path Traversal Vulnerability in Sametime Mobile App by HCL Tech
CVE-2021-27753

5.5MEDIUM

Key Information:

Vendor
CVE Published:
21 February 2022

Summary

The vulnerability in the HCL Sametime Android application allows attackers to exploit path traversal issues, potentially leading to unauthorized access to sensitive files stored on the device. This flaw can be used to manipulate file paths and access directories that should be restricted, raising significant security concerns for users of the mobile application.

Affected Version(s)

"HCL Sametime" "HCL Sametime 11.6.4 and below"

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.