CVE-2022-42445: HCL Launch is vulnerable to Insufficiently Protected LDAP Search Credentials (CVE-2022-42445)
HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-42445?
CVE-2022-42445 is a vulnerability in HCL Launch that could allow a user with administrative privileges to recover a previously saved credential for performing authenticated LDAP searches.
How severe is CVE-2022-42445?
CVE-2022-42445 has a severity rating of 4.9, which is considered medium.
Which versions of HCL Launch are affected by CVE-2022-42445?
HCL Launch versions 6.2.7.0 to 6.2.7.17, 7.0.0.0 to 7.0.5.12, 7.1.0.0 to 7.1.2.8, and 7.2.0.0 to 7.2.3.1 are affected by CVE-2022-42445.
Can a user with administrative privileges exploit CVE-2022-42445?
Yes, a user with administrative privileges, including 'Manage Security' permissions, can exploit CVE-2022-42445.
How can I fix CVE-2022-42445 in HCL Launch?
To fix CVE-2022-42445 in HCL Launch, it is recommended to apply the necessary patches or updates provided by HCL Technologies.