Executive brief
HCL Connections, a social collaboration platform for businesses, is affected by a security flaw that could lead to the exposure of sensitive information. An authenticated user could potentially view data they are not authorized to see due to the system improperly handling certain requests. While the risk is rated as low, it could lead to minor unauthorized data disclosure within the organization.
Technical details
HCL Connections 8.0 is vulnerable to an information disclosure flaw (CWE-209) resulting from the generation of error messages containing sensitive information. The vulnerability is caused by the improper handling of request data, which may leak internal system details or other sensitive data to an authenticated user. An attacker with low privileges can exploit this over the network, though it requires some level of user interaction (UI:R). The impact is limited to a partial loss of confidentiality (C:L) with no impact on integrity or availability. HCL has released a security update to address this issue.
Affected products
- HCL Software Connections 8.0
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory