CVE-2021-27751: HCL Commerce is affected by an Insufficient Session Expiration vulnerability.
Published May 6, 2022
·Updated
HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.
Affected Software
3 affected components
Hcltechsw Hcl Commerce>=8.0.0.0<8.0.4.28
Hcltechsw Hcl Commerce>=9.0.0.0<9.0.1.18
Hcltechsw Hcl Commerce>=9.1.0<9.1.9
Event History
May 6, 2022
CVE Published
via MITRE·06:10 PM
Data Sourced
via MITRE·06:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-27751?
CVE-2021-27751 is an Insufficient Session Expiration vulnerability in HCL Commerce.
2
What is the severity of CVE-2021-27751?
CVE-2021-27751 has a severity of medium.
3
Which versions of HCL Commerce are affected by CVE-2021-27751?
Versions 8.0.0.0 to 8.0.4.28, 9.0.0.0 to 9.0.1.18, and 9.1.0 to 9.1.9 of HCL Commerce are affected by CVE-2021-27751.
4
How does CVE-2021-27751 affect HCL Commerce?
After the session expires, in some circumstances, parts of the HCL Commerce application are still accessible.
5
How can I fix CVE-2021-27751 in HCL Commerce?
To fix CVE-2021-27751, update HCL Commerce to a version that is not affected by the vulnerability.