3.5

CVE-2025-52603

HCL Connections is vulnerable to information disclosure

HCL Connections is vulnerable to information disclosure.  In a very specific user navigation scenario, this could allow a user to obtain limited information when a single piece of internal metadata is returned in the browser.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Connections Version 7.0
Hcltech ≫ Connections Version 8.0 Update -
Hcltech ≫ Connections Version 8.0 Update cumulative_release1
Hcltech ≫ Connections Version 8.0 Update cumulative_release10
Hcltech ≫ Connections Version 8.0 Update cumulative_release2
Hcltech ≫ Connections Version 8.0 Update cumulative_release3
Hcltech ≫ Connections Version 8.0 Update cumulative_release4
Hcltech ≫ Connections Version 8.0 Update cumulative_release5
Hcltech ≫ Connections Version 8.0 Update cumulative_release6
Hcltech ≫ Connections Version 8.0 Update cumulative_release7
Hcltech ≫ Connections Version 8.0 Update cumulative_release8
Hcltech ≫ Connections Version 8.0 Update cumulative_release9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.166
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@hcl.com 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
CWE-213 Exposure of Sensitive Information Due to Incompatible Policies

The product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.

https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124242
Vendor Advisory