First published: Fri Jul 01 2022(Updated: )
HCL Launch stores user credentials in plain clear text which can be read by a local user.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Launch | =7.0.5.10 | |
HCL Launch | =7.1.2.6 | |
HCL Launch | =7.2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27548 is a vulnerability in HCL Launch where user credentials are stored in plain clear text, making them readable by a local user.
HCL Launch versions 7.0.5.10, 7.1.2.6, and 7.2.2.1 are affected by CVE-2022-27548.
CVE-2022-27548 has a severity rating of medium, with a severity value of 5.5.
An attacker with local access to the system can read user credentials stored in plain clear text.
Yes, it is recommended to update HCL Launch to a version that addresses the vulnerability and stores user credentials securely.