CVE-2023-28022: HCL Connections is vulnerable to sensitive information disclosure
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28022?
CVE-2023-28022 is classified as an information disclosure vulnerability, which poses significant risks to sensitive information.
How do I fix CVE-2023-28022?
To remediate CVE-2023-28022, it is recommended to apply the latest security patches provided by HCL Tech for affected versions of HCL Connections.
Which versions of HCL Connections are affected by CVE-2023-28022?
CVE-2023-28022 affects HCL Connections versions 6.0, 6.5, 7.0, and 8.0.
What type of risk does CVE-2023-28022 present?
CVE-2023-28022 presents a risk of unauthorized access to sensitive information due to improper handling of request data.
Is there a workaround for CVE-2023-28022 pending a fix?
Currently, there are no publicly documented workarounds for CVE-2023-28022; applying patches is the best course of action.