Sensitive Information Disclosure in HCL Connections Docs Software
CVE-2024-23563
3.9LOW
Key Information:
- Vendor
- HCL Software Software
- Status
- Connections Docs
- Vendor
- CVE Published:
- 12 February 2025
Summary
HCL Connections Docs is susceptible to a vulnerability that allows unauthorized users to access sensitive information due to improper handling of request data. This flaw may lead to potential data breaches, revealing confidential information that users should not have access to, thereby compromising user privacy and the overall integrity of the application.
Affected Version(s)
Connections Docs 2.0.2
References
CVSS V3.1
Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved