First published: Fri Aug 13 2021(Updated: )
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltechsw Hcl Commerce | >=8.0.4.0<=8.0.4.26 | |
Hcltechsw Hcl Commerce | >=9.0.1.0<=9.0.1.15 | |
Hcltechsw Hcl Commerce | >=9.1<=9.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-27741 is critical with a severity value of 9.1.
CVE-2021-27741 allows XML external entity (XXE) injection in HCL Commerce Management Center.
CVE-2021-27741 affects HCL Commerce versions 8.0.4.0 to 8.0.4.26, 9.0.1.0 to 9.0.1.15, and 9.1 to 9.1.5.
To fix CVE-2021-27741 in HCL Commerce Management Center, it is recommended to apply the latest security patch or upgrade to a patched version provided by HCL Technologies.
You can find more information about CVE-2021-27741 in the knowledge base article at the following link: [https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0089834](https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0089834).