HCL Commerce Security Vulnerability Could Lead to Denial of Service, Data Disclosure, and Unauthorized Admin Access
CVE-2024-23576

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
14 May 2024

Summary

The security vulnerability identified in specific versions of HCL Commerce can lead to significant risks, including potential denial of service and unauthorized access to sensitive user personal data. This issue affects versions 9.1.12 and 9.1.13, creating opportunities for malicious actors to exploit administrative operations without proper authorization. Organizations utilizing these versions are advised to be aware of the implicated risks and implement mitigation strategies promptly.

Affected Version(s)

Commerce 9.1.12, 9.1.13

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.