Sensitive Information Disclosure in HCL Connections Docs Software
CVE-2024-23563

3.9LOW

Key Information:

Vendor
HCL Software Software
Status
Connections Docs
Vendor
CVE Published:
12 February 2025

Summary

HCL Connections Docs is susceptible to a vulnerability that allows unauthorized users to access sensitive information due to improper handling of request data. This flaw may lead to potential data breaches, revealing confidential information that users should not have access to, thereby compromising user privacy and the overall integrity of the application.

Affected Version(s)

Connections Docs 2.0.2

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.