VendorsHcltechswhcl_commerceany version
Vulnerabilities

Hcltechsw HCL Software HCL Commerce any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2020-14275
Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
Published 2021-01-12 · Modified
9.8EPSS 0.014
CVE-2022-38656
HCL Commerce, when using Elasticsearch, could be affected by a denial of service vulnerability
Published 2022-11-04 · Modified
9.8EPSS 0.007
CVE-2021-27741
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
Published 2021-08-13 · Modified
9.1EPSS 0.012
CVE-2020-14274
Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.
Published 2021-01-12 · Modified
7.5EPSS 0.013
CVE-2024-23576
HCL Commerce is potentially affected by a denial of service and information disclosure vulnerability
Published 2024-05-13 · Analyzed
7.1EPSS 0.005
CVE-2021-27785
HCL Commerce could allow a local attacker to obtain sensitive personal information (CVE-2021-27785)
Published 2022-07-29 · Modified
5.0EPSS 0.002
CVE-2021-27751
HCL Commerce is affected by an Insufficient Session Expiration vulnerability.
Published 2022-05-06 · Modified
4.4EPSS 0.002