Impact
HCL Commerce contains a privilege escalation flaw that can cause a denial of service, reveal personal user data, and let an attacker carry out unauthorized administrative tasks. The weakness is improper privilege management (CWE‑266), allowing an authenticated user to gain higher level rights without proper authorization.
Affected Systems
The vulnerability affects HCL Commerce from HCLSoftware. No version information is provided, so any deployment of HCL Commerce could be impacted. Administrators should verify the specific product version against the vendor’s advisory and apply any available fix.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity. The EPSS score is less than 1 %, suggesting a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker who already has valid user credentials exploiting the privilege escalation flaw to gain administrative privileges, which could enable denial of service and data disclosure. Although exploitation likelihood is low, the risk remains significant until a vendor patch is installed or other controls are in place.
OpenCVE Enrichment