Vulnerability Database

309,130

Total vulnerabilities in the database

CVE-2024-23557

HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack.

  • Published: Apr 18, 2024
  • Updated: Nov 4, 2025
  • CVE: CVE-2024-23557
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 3.5
  • AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

CWEs:

Software From Fixed in
hcltech / connections 7.0 7.0.x
hcltech / connections 8.0 8.0.x
hcltech / connections 8.0-cumulative_release1 8.0-cumulative_release1.x
hcltech / connections 8.0-cumulative_release2 8.0-cumulative_release2.x
hcltech / connections 8.0-cumulative_release3 8.0-cumulative_release3.x
hcltech / connections 8.0-cumulative_release4 8.0-cumulative_release4.x