First published: Fri Dec 15 2023(Updated: )
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections | =6.0 | |
IBM Connections | =6.5 | |
IBM Connections | =7.0 | |
IBM Connections | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28022 is classified as an information disclosure vulnerability, which poses significant risks to sensitive information.
To remediate CVE-2023-28022, it is recommended to apply the latest security patches provided by HCL Tech for affected versions of HCL Connections.
CVE-2023-28022 affects HCL Connections versions 6.0, 6.5, 7.0, and 8.0.
CVE-2023-28022 presents a risk of unauthorized access to sensitive information due to improper handling of request data.
Currently, there are no publicly documented workarounds for CVE-2023-28022; applying patches is the best course of action.