Executive brief
HCL iReflection, a web-based application, was found to be using outdated third-party software components that contain known security flaws. While the risk is rated as low, using obsolete libraries can potentially allow unauthorized users to perform minor unauthorized modifications to data. Organizations using this software should review the vendor's support portal for updates to ensure all underlying components are current and secure.
Technical details
HCL iReflection contains a vulnerability stemming from the inclusion of outdated third-party libraries or components with known security issues. The vulnerability is accessible over the network but requires low-level privileges and involves high complexity to exploit. According to the CVSS vector, an attacker could potentially achieve a limited impact on data integrity, though confidentiality and availability are not affected. Users are advised to refer to HCL Software's KB0130981 for specific remediation steps and version information.
Affected products
- HCL Software iReflection
Timeline
- 2026-06-02: advisory: Initial advisory published by HCL Software and NVD.