CVE-2025-31966 LOW

CVE-2025-31966: Boolean-Based SQL Injection in Multiple Unica Components

Vendor Hcl
Product Sametime
Weakness CWE-20 · Input validation
Published March 17, 2026
Last update March 17, 2026

CVSS base score

2.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.

Key dates

02Disclosure timeline

March 17, 2026 CVE published
March 17, 2026 Record updated