HCL Commerce Security Vulnerability Could Lead to Denial of Service, Data Disclosure, and Unauthorized Admin Access
CVE-2024-23576 
7.1HIGH
What is CVE-2024-23576?
The security vulnerability identified in specific versions of HCL Commerce can lead to significant risks, including potential denial of service and unauthorized access to sensitive user personal data. This issue affects versions 9.1.12 and 9.1.13, creating opportunities for malicious actors to exploit administrative operations without proper authorization. Organizations utilizing these versions are advised to be aware of the implicated risks and implement mitigation strategies promptly.
Affected Version(s)
Commerce 9.1.12, 9.1.13