PT-2021-9706 · Hcl · Hcl Digital Experience
Published
2021-02-02
·
Updated
2021-07-21
·
CVE-2020-14255
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HCL Digital Experience version 9.5
Description
The issue affects HCL Digital Experience 9.5 containers, potentially exposing sensitive data to unauthorized parties through crafted requests. This issue is specific to containers and does not impact traditional on-premise installations.
Recommendations
For HCL Digital Experience version 9.5, consider restricting access to crafted requests until a fix is available. As a temporary workaround, review and secure container configurations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hcl Digital Experience