CVE-2023-37532: A path traversal vulnerability affects HCL Commerce
Published Oct 23, 2023
·Updated
HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.
Affected Software
1 affected component
hcltech Commerce>=9.1.8<=9.1.13.2
Event History
Oct 23, 2023
CVE Published
04:34 PM
Data Sourced
04:34 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2023-37532?
CVE-2023-37532 is a path traversal vulnerability affecting HCL Commerce Remote Store server.
2
How does CVE-2023-37532 exploit work?
An attacker can exploit CVE-2023-37532 by crafting a special URL to read arbitrary files on the system.
3
What is the severity of CVE-2023-37532?
CVE-2023-37532 has a severity rating of medium with a CVSSv3 score of 5.8.
4
Which versions of HCL Commerce are affected by CVE-2023-37532?
CVE-2023-37532 affects HCL Commerce versions from 9.1.8 to 9.1.13.2.
5
How can I fix CVE-2023-37532?
To fix CVE-2023-37532, update HCL Commerce to a version outside the affected range or apply any available patches or mitigations provided by HCL Tech.