---
id: CVE-2025-32000
title: HCL Sametime is vulnerable to insufficient input sanitization
summary: >-
  HCL Sametime is vulnerable to insufficient input sanitization. The application
  did not appropriately sanitize user input. When user input is implicitly or
  explicitly trusted without sufficient sanitization, malicious actors can
  leverage …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-20
vendor: HCL Software
product: HCL Sametime
affected:
  - hcl_sametime 12.0.33 and older
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:17:43.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-32000'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132652
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T15:35:48.370418Z'
ingestedAt: '2026-09-24T15:45:56.654Z'
epss: 0.00213
epssPercentile: 0.104
---

## Overview

HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly trusted without sufficient sanitization, malicious actors can leverage this vulnerability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
