HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0115627