Open Redirect Vulnerability in HCL Connections Products
CVE-2019-4209

6.1MEDIUM

Key Information:

Vendor
CVE Published:
1 May 2020

Summary

HCL Connections versions 5.5, 6.0, and 6.5 are susceptible to an open redirect vulnerability. This flaw can be exploited by attackers to redirect users to malicious sites, potentially facilitating phishing scams. When users interact with compromised links, they may unknowingly provide sensitive information or credentials to the attacker. It is essential for organizations using these versions to implement security measures and apply relevant patches to safeguard against such threats.

Affected Version(s)

HCL Connections v5.5

HCL Connections v6.0

HCL Connections v6.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.