PT-2021-9706 · Hcl · Hcl Digital Experience

Published

2021-02-02

·

Updated

2021-07-21

·

CVE-2020-14255

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HCL Digital Experience version 9.5
Description The issue affects HCL Digital Experience 9.5 containers, potentially exposing sensitive data to unauthorized parties through crafted requests. This issue is specific to containers and does not impact traditional on-premise installations.
Recommendations For HCL Digital Experience version 9.5, consider restricting access to crafted requests until a fix is available. As a temporary workaround, review and secure container configurations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-14255

Affected Products

Hcl Digital Experience