CVE-2022-27548: HCL Launch is vulnerable to information disclosure which can be read by a local user.
Published Jul 6, 2022
·Updated
HCL Launch stores user credentials in plain clear text which can be read by a local user.
Affected Software
3 affected components
Hcltechsw Hcl Launch=7.0.5.10
Hcltechsw Hcl Launch=7.1.2.6
Hcltechsw Hcl Launch=7.2.2.1
Event History
Jul 6, 2022
CVE Published
via MITRE·08:25 PM
Data Sourced
via MITRE·08:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-27548?
CVE-2022-27548 is a vulnerability in HCL Launch where user credentials are stored in plain clear text, making them readable by a local user.
2
Which software versions are affected by CVE-2022-27548?
HCL Launch versions 7.0.5.10, 7.1.2.6, and 7.2.2.1 are affected by CVE-2022-27548.
3
What is the severity of CVE-2022-27548?
CVE-2022-27548 has a severity rating of medium, with a severity value of 5.5.
4
How can an attacker exploit CVE-2022-27548?
An attacker with local access to the system can read user credentials stored in plain clear text.
5
Is there a fix for CVE-2022-27548?
Yes, it is recommended to update HCL Launch to a version that addresses the vulnerability and stores user credentials securely.