Impact
HCL Connections allows a server‑side request forgery (SSRF) that can be used when an attacker compromises an internal server or exploits certain vulnerable interfaces. The flaw can enable the attacker to instruct the Connections server to make unauthorized HTTP requests to internal or external resources, potentially leading to information disclosure or bypass of security controls. The weakness is classified as CWE‑918 and is represented by a CVSS score of 3.7, indicating low overall severity but non‑negligible impact if exploited in the right environment.
Affected Systems
This vulnerability affects the HCL Software Connections platform as identified by the CNA. No specific product versions are listed in the advisory, so all publicly available releases should be considered potentially affected until a vendor statement clarifies the scope.
Risk and Exploitability
The CVSS score of 3.7 reflects a low likelihood of successful exploitation in a general sense, yet the EPSS score is not available and the issue is not present in the CISA KEV catalog, suggesting that exploitation has not yet been observed in the wild. However, the SSRF vector is commonly leveraged by attackers to access hidden internal resources or to pivot to other systems. The likely attack path involves submitting crafted input that is processed by the Connections server to reach internal endpoints; if the server is already compromised, this flaw expands the attacker’s reach to sensitive data or privileged services.
OpenCVE Enrichment