HCL Commerce, when using Elasticsearch, could be affected by a denial of service vulnerability
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.6epss 0.7%
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
nono source reports it
In short
HCL Commerce websites using Elasticsearch can be taken offline by attackers, who may also gain ability to make administrative changes. This is a serious flaw that affects site availability and security.
Technical detail
A remote attacker can trigger a denial of service condition in HCL Commerce deployments configured with Elasticsearch backend, potentially combined with unauthorized administrative access. The vulnerability requires network access to the affected service; exploitation results in service unavailability and potential privilege escalation through administrative function compromise.
Summary generated and translated by AI from the official description.
HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Affected products
HCL Software · HCL Commerce