CVE-2020-14274: High severity hcl commerce vulnerability
Published Jan 12, 2021
·Updated
Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.
Affected Software
2 affected components
Hcltechsw Hcl Commerce>=9.0.1.9<=9.0.1.14
Hcltechsw Hcl Commerce>=9.1<=9.1.4.0
Event History
Jan 12, 2021
CVE Published
via MITRE·02:29 PM
Data Sourced
via MITRE·02:29 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-14274?
CVE-2020-14274 is an information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4.
2
What is the severity of CVE-2020-14274?
The severity of CVE-2020-14274 is high with a severity value of 7.5.
3
How can a remote attacker exploit CVE-2020-14274?
A remote attacker can exploit CVE-2020-14274 to obtain user personal data via unknown vectors.
4
Which versions of HCL Commerce are affected by CVE-2020-14274?
HCL Commerce versions 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 are affected by CVE-2020-14274.
5
Is there a fix available for CVE-2020-14274?
Please refer to the official HCL Commerce support article for details on how to fix CVE-2020-14274.