Impact
An endpoint in HCL Connections is vulnerable to information disclosure, meaning that unauthorized users may be able to retrieve sensitive data from the system. The weakness is classified as CWE‑213, which involves insufficient protection of information the result of an unintended exposure. The impact is the leakage of confidential data that could compromise the privacy and integrity of users monitored by the service.
Affected Systems
The vulnerability affects the HCLSoftware Connections product. No specific version details are indicated in the advisory, so all deployed instances of this application may be at risk until a patch or update is released by the vendor.
Risk and Exploitability
The CVSS score of 3.5 indicates a low severity, and the EPSS score is below 1%, translating to a very low probability of exploitation. The flaw is not listed in CISA's KEV catalog, further suggesting it is unlikely to be actively exploited. The attack vector is inferred to be remote access to the vulnerable endpoint; an attacker must send crafted requests to the endpoint to cause the information disclosure. No public exploit or detailed attack path is documented in the available information.
OpenCVE Enrichment