5

CVE-2021-27785

HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.

Data is provided by the National Vulnerability Database (NVD)
HcltechswHcl Commerce Version >= 9.0.1 <= 9.0.1.18
HcltechswHcl Commerce Version >= 9.1.0 <= 9.1.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.194
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 1.3 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
psirt@hcl.com 3.9 0.5 3.4
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.