Path Traversal Vulnerability in Sametime Android by HCL Technologies
CVE-2021-27755
5.5MEDIUM
Summary
A path traversal vulnerability exists in the HCL Sametime Android application due to improper validation of file paths when using the File class. This flaw could allow a malicious actor to access restricted files or directories on the host system, potentially leading to unauthorized exposure of data. Users are advised to review the impacted versions and apply the necessary updates to mitigate risks associated with this vulnerability.
Affected Version(s)
"HCL Sametime" "HCL Sametime 11.6.4 and below"
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved