← back
CVE-2022-38656high

HCL Commerce, when using Elasticsearch, could be affected by a denial of service vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.6epss 0.7%
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
nono source reports it
In short

HCL Commerce websites using Elasticsearch can be taken offline by attackers, who may also gain ability to make administrative changes. This is a serious flaw that affects site availability and security.

Technical detail

A remote attacker can trigger a denial of service condition in HCL Commerce deployments configured with Elasticsearch backend, potentially combined with unauthorized administrative access. The vulnerability requires network access to the affected service; exploitation results in service unavailability and potential privilege escalation through administrative function compromise.

Summary generated and translated by AI from the official description.
HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H