HCL Connections
cpe:2.3:a:hcltech:connections:*:*:*:*:*:*:*, +2 more
- 7.0
- 8.0
A vulnerability allowing information disclosure has been identified in HCL Connections versions 7.0 and 8.0. This issue arises in specific user navigation scenarios, where a user may unintentionally access limited internal metadata through their browser.
Exploitation of this vulnerability could lead to unauthorized access to internal metadata, allowing users to obtain limited information that should not be publicly available.
Users of HCL Connections 8.0 should upgrade to Cumulative Fixpack HCL Connections v8.0 CR11 or later. Users of HCL Connections 7.0 should upgrade to the latest Cumulative Fixpack for HCL Connections v7.0 and install KB0124242.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.