Impact
HCL Connections has an information disclosure flaw that allows an attacker to read sensitive data they are not authorized to view. The root cause is improper handling of request data, which may expose confidential information. This weakness could enable attackers to obtain sensitive information, impacting confidentiality.
Affected Systems
This vulnerability affects HCL Connections from HCL Software. No specific version range is provided, so all deployments may be impacted until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 3.5 indicates low severity, and the EPSS score of < 1% (approximately 0.00156) and no KEV listing suggest a very low likelihood of exploitation. The attack vector appears to involve sending crafted requests to the application; if the service is publicly exposed, remote exploitation could be possible. Until a vendor fix is applied, the risk remains due to lack of mitigation.
OpenCVE Enrichment