CVE-2022-27551: HCL Launch could allow an authenticated user to obtain sensitive information (CVE-2022-27551)
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27551?
CVE-2022-27551 is a vulnerability in HCL Launch that could allow an authenticated user to obtain sensitive information due to improper security checking.
How can an authenticated user exploit CVE-2022-27551?
An authenticated user can exploit CVE-2022-27551 by performing certain actions that bypass security checks and access sensitive information.
What is the severity of CVE-2022-27551?
CVE-2022-27551 has a severity of medium with a CVSS score of 6.5.
Which versions of HCL Launch are affected by CVE-2022-27551?
HCL Launch versions between 7.0.0.0 and 7.0.5.12, between 7.1.0.0 and 7.1.2.8, and between 7.2.0.0 and 7.2.3.1 are affected by CVE-2022-27551.
How can I fix CVE-2022-27551?
To fix CVE-2022-27551, it is recommended to upgrade HCL Launch to a version that addresses the vulnerability and includes proper security checks.