HCL Commerce Security Vulnerability Could Lead to Denial of Service, Data Disclosure, and Unauthorized Admin Access
CVE-2024-23576
7.1HIGH
Summary
The security vulnerability identified in specific versions of HCL Commerce can lead to significant risks, including potential denial of service and unauthorized access to sensitive user personal data. This issue affects versions 9.1.12 and 9.1.13, creating opportunities for malicious actors to exploit administrative operations without proper authorization. Organizations utilizing these versions are advised to be aware of the implicated risks and implement mitigation strategies promptly.
Affected Version(s)
Commerce 9.1.12, 9.1.13
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved