CVE-2023-23348: HCL Launch is vulnerable to sensitive information disclosure
Published Jul 10, 2023
·Updated
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.
Affected Software
5 affected components
Hcltechsw Hcl Launch>=6.2.0.0<6.2.7.20
Hcltechsw Hcl Launch>=7.0.0.0<7.0.5.15
Hcltechsw Hcl Launch>=7.1.0.0<7.1.2.11
Hcltechsw Hcl Launch>=7.2.0.0<7.2.3.4
Hcltechsw Hcl Launch>=7.3.0.0<7.3.1.0
Event History
Jul 10, 2023
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionSeverity
Data Sourced
06:15 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this HCL Launch vulnerability?
The vulnerability ID of this HCL Launch vulnerability is CVE-2023-23348.
2
What is the severity level of CVE-2023-23348?
CVE-2023-23348 has a severity level of medium (5.5).
3
How can sensitive information be disclosed in HCL Launch due to this vulnerability?
Sensitive information can be disclosed in HCL Launch if a manual edit of a configuration file has been performed.
4
Which versions of HCL Launch are affected by CVE-2023-23348?
Versions 6.2.0.0 to 6.2.7.20, 7.0.0.0 to 7.0.5.15, 7.1.0.0 to 7.1.2.11, 7.2.0.0 to 7.2.3.4, and 7.3.0.0 to 7.3.1.0 of HCL Launch are affected by CVE-2023-23348.
5
Where can I find more information about CVE-2023-23348?
You can find more information about CVE-2023-23348 at the following link: [https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0105978](https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0105978)