CVE-2021-27785: HCL Commerce could allow a local attacker to obtain sensitive personal information (CVE-2021-27785)
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27785?
CVE-2021-27785 refers to a vulnerability in HCL Commerce's Remote Store server that could allow a local attacker to obtain sensitive personal information.
What is the severity of CVE-2021-27785?
CVE-2021-27785 has a severity level of medium, with a severity value of 5.
Which versions of HCL Commerce are affected by CVE-2021-27785?
CVE-2021-27785 affects HCL Commerce versions 9.0.1.18 and earlier, as well as versions 9.1.0 to 9.1.10.
How can a local attacker exploit CVE-2021-27785?
To exploit CVE-2021-27785, a local attacker would first need the victim to perform a specific operation on the website.
How can I fix CVE-2021-27785?
To address CVE-2021-27785, it is recommended to update HCL Commerce to a version that is not affected by the vulnerability.