{"id":"CVE-2025-32000","title":"HCL Sametime is vulnerable to insufficient input sanitization","summary":"HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly trusted without sufficient sanitization, malicious actors can leverage …","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","cwe":["CWE-20"],"vendor":"HCL Software","product":"HCL Sametime","affected":["hcl_sametime 12.0.33 and older"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T16:17:06.087","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-32000","references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132652","label":"psirt@hcl.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-24T15:35:48.370418Z"},"ingestedAt":"2026-09-24T15:45:56.654Z","slug":"CVE-2025-32000","body":"## Overview\n\nHCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly trusted without sufficient sanitization, malicious actors can leverage this vulnerability.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}