CVE-2021-27741

EUVD-2021-14482
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Affected Products (NVD)
VendorProductVersion
hcltechswhcl_commerce
8.0.4.0 ≤
𝑥
≤ 8.0.4.26
hcltechswhcl_commerce
9.0.1.0 ≤
𝑥
≤ 9.0.1.15
hcltechswhcl_commerce
9.1 ≤
𝑥
≤ 9.1.5
𝑥
= Vulnerable software versions