HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
History

Wed, 29 Oct 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech connections
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:hcltech:connections:7.0:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:connections:8.0:-:*:*:*:*:*:*
cpe:2.3:a:hcltech:connections:8.0:cumulative_release1:*:*:*:*:*:*
cpe:2.3:a:hcltech:connections:8.0:cumulative_release2:*:*:*:*:*:*
cpe:2.3:a:hcltech:connections:8.0:cumulative_release3:*:*:*:*:*:*
cpe:2.3:a:hcltech:connections:8.0:cumulative_release4:*:*:*:*:*:*
cpe:2.3:a:hcltech:connections:8.0:cumulative_release5:*:*:*:*:*:*
cpe:2.3:a:hcltech:connections:8.0:cumulative_release6:*:*:*:*:*:*
cpe:2.3:a:hcltech:connections:8.0:cumulative_release7:*:*:*:*:*:*
cpe:2.3:a:hcltech:connections:8.0:cumulative_release8:*:*:*:*:*:*
cpe:2.3:a:hcltech:connections:8.0:cumulative_release9:*:*:*:*:*:*
Vendors & Products Hcltech
Hcltech connections

Tue, 25 Feb 2025 23:30:00 +0000

Type Values Removed Values Added
Title HCL Connections is vulnerable to a broken access control vulnerability HCL Connections is vulnerable to broken access control
References

Mon, 04 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published: 2024-06-25T15:08:03.168Z

Updated: 2025-02-25T23:12:11.673Z

Reserved: 2023-07-06T16:29:45.713Z

Link: CVE-2023-37541

cve-icon Vulnrichment

Updated: 2024-08-02T17:16:30.496Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-25T15:15:11.363

Modified: 2025-10-29T14:45:51.547

Link: CVE-2023-37541

cve-icon Redhat

No data.