First published: Mon Aug 01 2022(Updated: )
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Launch | >=7.0.0.0<7.0.5.12 | |
HCL Launch | >=7.1.0.0<7.1.2.8 | |
HCL Launch | >=7.2.0.0<7.2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27551 is a vulnerability in HCL Launch that could allow an authenticated user to obtain sensitive information due to improper security checking.
An authenticated user can exploit CVE-2022-27551 by performing certain actions that bypass security checks and access sensitive information.
CVE-2022-27551 has a severity of medium with a CVSS score of 6.5.
HCL Launch versions between 7.0.0.0 and 7.0.5.12, between 7.1.0.0 and 7.1.2.8, and between 7.2.0.0 and 7.2.3.1 are affected by CVE-2022-27551.
To fix CVE-2022-27551, it is recommended to upgrade HCL Launch to a version that addresses the vulnerability and includes proper security checks.