Server-Side Request Forgery Vulnerability in HCL Connections by HCL Software
CVE-2025-62341

3.7LOW

Key Information:

Vendor
CVE Published:
26 August 2026

What is CVE-2025-62341?

HCL Connections contains a vulnerability that allows for server-side request forgery (SSRF) attacks, potentially enabling an attacker to exploit compromised internal servers. This could result in unauthorized requests being sent under specific circumstances, leading to risks of information exposure or security protections being bypassed.

Affected Version(s)

Connections 7.0, 8.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.