First published: Thu Apr 18 2024(Updated: )
HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23557 is a medium severity vulnerability that allows user enumeration in HCL Connections.
To mitigate CVE-2024-23557, implement access control measures and restrict user enumeration techniques within HCL Connections.
CVE-2024-23557 can potentially lead to brute force attacks due to the ability to verify valid user accounts.
Check with HCL for any patches or updates that address CVE-2024-23557 in HCL Connections.
All users and administrators of HCL Connections may be affected by CVE-2024-23557 due to its user enumeration capabilities.