HCL Commerce is affected by an Insufficient Session Expiration vulnerability.
CVE-2021-27751
4.4MEDIUM
Summary
HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.
Affected Version(s)
HCL Commerce 8.0 - 8.0.4.27
HCL Commerce 9.0 - 9.0.1.17
HCL Commerce 9.1.0 - 9.1.8
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved