HCL Leap Anonymous Directory Access Vulnerability

Vulnerability

A vulnerability exists in HCL Leap versions 9.0 prior to 9.3.5, allowing anonymous users to access directory information due to an insufficient default configuration. This could lead to unauthorized exposure of directory details.

Impact

Exploitation of this vulnerability could result in unauthorized access to directory information, potentially exposing sensitive data or user details.

Remediation

Users can upgrade to HCL Leap version 9.3.5 or higher to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.