Lucene search

K
cvelistHCLCVELIST:CVE-2021-27751
HistoryMay 06, 2022 - 6:10 p.m.

CVE-2021-27751 HCL Commerce is affected by an Insufficient Session Expiration vulnerability.

2022-05-0618:10:26
CWE-613
HCL
www.cve.org
4
hcl commerce
insufficient session expiration

CVSS3

4.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

AI Score

5.1

Confidence

High

EPSS

0

Percentile

12.6%

HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.

CNA Affected

[
  {
    "product": "HCL Commerce",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "8.0 - 8.0.4.27"
      },
      {
        "status": "affected",
        "version": "9.0 - 9.0.1.17"
      },
      {
        "status": "affected",
        "version": "9.1.0 - 9.1.8"
      }
    ]
  }
]

CVSS3

4.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

AI Score

5.1

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVELIST:CVE-2021-27751