Lucene search

K
cveHCLCVE-2024-23576
HistoryMay 14, 2024 - 2:59 p.m.

CVE-2024-23576

2024-05-1414:59:48
CWE-285
HCL
web.nvd.nist.gov
22
hcl commerce
vulnerability
denial of service
user data disclosure
unauthorized operations

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

9.0%

Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Commerce",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "9.1.12, 9.1.13"
      }
    ]
  }
]

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

9.0%

Related for CVE-2024-23576