VYPR
Low severity3.5NVD Advisory· Published Feb 20, 2026· Updated Jun 17, 2026

CVE-2025-52603

CVE-2025-52603

Description

HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow a user to obtain limited information when a single piece of internal metadata is returned in the browser.

Affected products

14
  • HCLTech/Connections12 versions
    cpe:2.3:a:hcltech:connections:7.0:*:*:*:*:*:*:*+ 11 more
    • cpe:2.3:a:hcltech:connections:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:connections:8.0:-:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:connections:8.0:cumulative_release10:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:connections:8.0:cumulative_release1:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:connections:8.0:cumulative_release2:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:connections:8.0:cumulative_release3:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:connections:8.0:cumulative_release4:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:connections:8.0:cumulative_release5:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:connections:8.0:cumulative_release6:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:connections:8.0:cumulative_release7:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:connections:8.0:cumulative_release8:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:connections:8.0:cumulative_release9:*:*:*:*:*:*
  • Range: 7.0, 8.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.