Vulnerability Description
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hcltechsw | Hcl Commerce | >= 9.0.1, <= 9.0.1.18 |
Related Weaknesses (CWE)
References
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0099765Vendor Advisory
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0099765Vendor Advisory
FAQ
What is CVE-2021-27785?
CVE-2021-27785 is a vulnerability with a CVSS score of 3.9 (LOW). HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.
How severe is CVE-2021-27785?
CVE-2021-27785 has been rated LOW with a CVSS base score of 3.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27785?
Check the references section above for vendor advisories and patch information. Affected products include: Hcltechsw Hcl Commerce.