Path Traversal Vulnerability in Sametime Mobile App by HCL Tech
CVE-2021-27753
5.5MEDIUM
Summary
The vulnerability in the HCL Sametime Android application allows attackers to exploit path traversal issues, potentially leading to unauthorized access to sensitive files stored on the device. This flaw can be used to manipulate file paths and access directories that should be restricted, raising significant security concerns for users of the mobile application.
Affected Version(s)
"HCL Sametime" "HCL Sametime 11.6.4 and below"
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved