Impact
A default login portlet in HCL Digital Experience and Digital Experience Compose fails to adequately protect credentials. In certain specific configurations, the portlet writes sensitive information to web server logs. This can expose usernames, passwords, or other authentication data to anyone with access to these log files, compromising confidentiality and potentially allowing further compromise.
Affected Systems
The vulnerability affects installations of HCL Digital Experience and Digital Experience Compose that use the default login portlet. No specific product versions are listed, but it applies to any configuration that enables the portlet’s default behavior of logging credential data to the web server.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited or undocumented exploitation. The likely attack vector involves interacting with the insecure login portlet, triggering the use of the portlet’s default logging behavior. If an attacker can view or obtain the web server’s log files, credential data may be retrieved. The medium CVSS score and absence of known exploits imply that the risk is moderate but could be serious if effective log access is achieved.
OpenCVE Enrichment