CVE-2023-45720: HCL Leap is affected by a disclosure of private personal information vulnerability
Published Apr 24, 2025
·Updated
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
Affected Software
2 affected components
HCL Leap
hcltech Hcl Leap<9.3.5
Event History
Apr 24, 2025
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-45720?
CVE-2023-45720 is classified as a moderate severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2023-45720?
To remediate CVE-2023-45720, ensure proper authentication and access controls are configured for HCL Leap deployments.
3
What are the risks associated with CVE-2023-45720?
The key risk of CVE-2023-45720 is that it allows unauthorized users to access sensitive directory information.
4
Which versions of HCL Leap are affected by CVE-2023-45720?
CVE-2023-45720 affects all versions of HCL Leap that have insufficient default configuration.
5
Can anonymous users exploit CVE-2023-45720?
Yes, CVE-2023-45720 can be exploited by anonymous users if proper security measures are not in place.