« Volver al listado

CVE-2023-45698

Estado: ModificadaMedia (6.1)—

Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-45698",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-45698",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-17T19:55:03.446449Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@hcl.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@hcl.com",
      "affectedData": [
        {
          "vendor": "HCL Software",
          "product": "HCL Sametime",
          "versions": [
            {
              "status": "affected",
              "version": "11.5, 11.6, 11.6 IF1, 12.0, 12.0 FP1, 12.0.1, 12.0.1 FP1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-02-10T04:15:07.280",
  "references": [
    {
      "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109082",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@hcl.com"
    },
    {
      "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0109082",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1021"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1021"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.\n"
    },
    {
      "lang": "es",
      "value": "Sametime se ve afectado por la falta de protección contra el secuestro de clics en el complemento de Outlook. La aplicación no implementa protecciones adecuadas para proteger a los usuarios de ataques de clickjacking."
    }
  ],
  "lastModified": "2026-06-17T06:29:22.920",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hcltech:sametime_chat_and_meetings:11.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07933AF5-4BA3-46B0-B53F-D77C859B6BDF"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:sametime_chat_and_meetings:11.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6FF14F0-8D44-40B7-8F4F-1852BE5B1C6E"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:sametime_chat_and_meetings:11.6:if1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64E0F6DC-6AE4-4DFC-A28D-875612CB7C3A"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:sametime_chat_and_meetings:12.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56D463AB-C94D-44EF-8663-749F2687CD56"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:sametime_chat_and_meetings:12.0:fp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C362AEE6-7F7A-4E71-8C6E-064AB6016F89"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:sametime_chat_and_meetings:12.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D62DFD9-0B97-43F7-B7D1-97E5D68C5562"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:sametime_chat_and_meetings:12.0.1:fp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66E4C551-C527-4B5F-A4F7-F72A3CA6BF3C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@hcl.com"
}