Impact
The vulnerability arises from HCL Connections improperly processing request data that users do not have permission to access. This flaw allows an attacker to read sensitive information that should be restricted, resulting in an information disclosure scenario. The weakness is classified under CWE‑359, indicating insufficient verification of data authenticity.
Affected Systems
Affected systems are deployments of HCL Connections from HCLSoftware. The specific version range that is vulnerable is not listed in the advisory, so any installation running an unpatched or older version may be impacted. Administrators should verify their installation version against the vendor’s support page for a patch or newer release.
Risk and Exploitability
The CVSS score of 3.1 indicates low overall risk, and there is no evidence that exploitation is currently in use or listed in CISA KEV catalog. The EPSS score is not available, so the probability of exploitation is unknown. Because the advisory does not specify an attack vector, the likely path would involve a user submitting a request that includes unauthorized data; the flaw is exploitable only if the system allows such request processing. In the absence of exploitation evidence, the threat is low but should still be addressed promptly to prevent accidental disclosure.
OpenCVE Enrichment