First published: Mon Oct 23 2023(Updated: )
HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Commerce | >=9.1.8<=9.1.13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37532 is a path traversal vulnerability affecting HCL Commerce Remote Store server.
An attacker can exploit CVE-2023-37532 by crafting a special URL to read arbitrary files on the system.
CVE-2023-37532 has a severity rating of medium with a CVSSv3 score of 5.8.
CVE-2023-37532 affects HCL Commerce versions from 9.1.8 to 9.1.13.2.
To fix CVE-2023-37532, update HCL Commerce to a version outside the affected range or apply any available patches or mitigations provided by HCL Tech.