CVE-2022-38656: HCL Commerce, when using Elasticsearch, could be affected by a denial of service vulnerability
Published Nov 4, 2022
·Updated
HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.
Affected Software
1 affected component
Hcltechsw Hcl Commerce>=9.1.8<=9.1.11
Event History
Nov 4, 2022
CVE Published
via MITRE·08:58 PM
Data Sourced
via MITRE·08:58 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this HCL Commerce vulnerability?
The vulnerability ID for this HCL Commerce vulnerability is CVE-2022-38656.
2
What is the title of this HCL Commerce vulnerability?
The title of this HCL Commerce vulnerability is 'HCL Commerce when using Elasticsearch can allow a remote attacker to cause a denial of service attack.'
3
What is the severity rating of vulnerability CVE-2022-38656?
The severity rating of vulnerability CVE-2022-38656 is critical with a severity value of 9.8.
4
What is the affected software for vulnerability CVE-2022-38656?
The affected software for vulnerability CVE-2022-38656 is HCL Commerce version 9.1.8 to 9.1.11 when using Elasticsearch.
5
How can this vulnerability be exploited?
This vulnerability can be exploited by a remote attacker to cause a denial of service attack on the site and make administrative changes.