First published: Fri Jul 29 2022(Updated: )
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltechsw Hcl Commerce | >=9.0.1<=9.0.1.18 | |
Hcltechsw Hcl Commerce | >=9.1.0<=9.1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27785 refers to a vulnerability in HCL Commerce's Remote Store server that could allow a local attacker to obtain sensitive personal information.
CVE-2021-27785 has a severity level of medium, with a severity value of 5.
CVE-2021-27785 affects HCL Commerce versions 9.0.1.18 and earlier, as well as versions 9.1.0 to 9.1.10.
To exploit CVE-2021-27785, a local attacker would first need the victim to perform a specific operation on the website.
To address CVE-2021-27785, it is recommended to update HCL Commerce to a version that is not affected by the vulnerability.