PT-2021-9710 · Hcl · Hcl Commerce

Published

2021-01-12

·

Updated

2021-01-14

·

CVE-2020-14275

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HCL Commerce versions 9.0.0.5 through 9.0.0.13 HCL Commerce versions 9.0.1.0 through 9.0.1.14 HCL Commerce versions 9.1 through 9.1.4
Description The issue could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
Recommendations For HCL Commerce versions 9.0.0.5 through 9.0.0.13, update to a version outside of this range to resolve the issue. For HCL Commerce versions 9.0.1.0 through 9.0.1.14, update to a version outside of this range to resolve the issue. For HCL Commerce versions 9.1 through 9.1.4, update to a version outside of this range to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-14275

Affected Products

Hcl Commerce