Hcltechsw
Hcltechsw HCL Commerce: vulnerabilidades y CVE
Hcltechsw HCL Commerce tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-23576 | Alta (7.1) | 0.45% | — | 14 may 2024 | Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations. |
| CVE-2022-38656 | Crítica (9.8) | 0.73% | — | 12 dic 2022 | HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes. |
| CVE-2021-27785 | Media (5) | 0.18% | — | 30 jul 2022 | HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website. |
| CVE-2021-27751 | Baja (3.3) | 0.19% | — | 6 may 2022 | HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible. |
| CVE-2021-27741 | Crítica (9.1) | 1.2% | — | 13 ago 2021 | " Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection" |
| CVE-2020-14275 | Crítica (9.8) | 1.4% | — | 12 ene 2021 | Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized… |
| CVE-2020-14274 | Alta (7.5) | 1.3% | — | 12 ene 2021 | Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors. |