First published: Tue Apr 05 2022(Updated: )
HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Commerce | >=8.0.0.0<8.0.4.28 | |
HCL Commerce | >=9.0.0.0<9.0.1.18 | |
HCL Commerce | >=9.1.0<9.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27751 is an Insufficient Session Expiration vulnerability in HCL Commerce.
CVE-2021-27751 has a severity of medium.
Versions 8.0.0.0 to 8.0.4.28, 9.0.0.0 to 9.0.1.18, and 9.1.0 to 9.1.9 of HCL Commerce are affected by CVE-2021-27751.
After the session expires, in some circumstances, parts of the HCL Commerce application are still accessible.
To fix CVE-2021-27751, update HCL Commerce to a version that is not affected by the vulnerability.