HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack.
| Software | From | Fixed in |
|---|---|---|
| hcltech / connections | 7.0 | 7.0.x |
| hcltech / connections | 8.0 | 8.0.x |
| hcltech / connections | 8.0-cumulative_release1 | 8.0-cumulative_release1.x |
| hcltech / connections | 8.0-cumulative_release2 | 8.0-cumulative_release2.x |
| hcltech / connections | 8.0-cumulative_release3 | 8.0-cumulative_release3.x |
| hcltech / connections | 8.0-cumulative_release4 | 8.0-cumulative_release4.x |