CVE-2025-52603: HCL Connections is vulnerable to information disclosure
HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow a user to obtain limited information when a single piece of internal metadata is returned in the browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52603?
CVE-2025-52603 is classified as a moderate severity vulnerability due to the potential information disclosure risk.
How do I fix CVE-2025-52603?
To mitigate CVE-2025-52603, ensure that you have implemented the latest security patches provided by HCL for Connections.
Which versions of HCL Connections are affected by CVE-2025-52603?
CVE-2025-52603 affects HCL Connections versions 7.0, 8.0, and several cumulative releases of 8.0.
What type of information can be disclosed due to CVE-2025-52603?
CVE-2025-52603 may allow the disclosure of limited internal metadata through specific user navigation scenarios.
Is user action required to trigger the CVE-2025-52603 vulnerability?
Yes, CVE-2025-52603 requires a specific user navigation scenario to potentially exploit the information disclosure vulnerability.