CVE-2025-62341
Received Received - Intake

HCL Connections SSRF Vulnerability Leading to Information Disclosure

Vulnerability report for CVE-2025-62341, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: HCL Software

Description

HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to information disclosure or security bypass.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl connections *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HCL Connections has a server-side request forgery (SSRF) vulnerability. This allows an attacker to trick the server into making unauthorized requests to internal systems. If an internal server is compromised, the attacker could send requests that lead to information disclosure or bypass security controls.

Impact Analysis

This vulnerability could allow an attacker to access sensitive internal information or bypass security measures. The impact depends on the internal systems and data accessible from the compromised server. The CVSS score suggests a moderate risk with low impact on confidentiality and integrity.

Compliance Impact

SSRF vulnerabilities can lead to unauthorized access to sensitive data, which may violate compliance requirements like GDPR or HIPAA. If exploited, this could result in data breaches, unauthorized data exposure, or failure to protect personal health or user data, leading to legal and regulatory penalties.

Mitigation Strategies

Apply patches or updates from HCL Connections to address the SSRF vulnerability. Restrict internal server access and monitor network traffic for unauthorized requests. Review and update firewall rules to limit outbound connections from affected systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-62341. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart