{"api_version":"1","generated_at":"2026-07-23T22:02:15+00:00","cve":"CVE-2020-14275","urls":{"html":"https://cve.report/CVE-2020-14275","api":"https://cve.report/api/cve/CVE-2020-14275.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-14275","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-14275"},"summary":{"title":"CVE-2020-14275","description":"Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.","state":"PUBLIC","assigner":"psirt@hcl.com","published_at":"2021-01-12 15:15:00","updated_at":"2021-01-14 01:22:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0086271","name":"https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0086271","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"%short_descr - Customer Support","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-14275","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-14275","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"14275","vulnerable":"1","versionEndIncluding":"9.0.0.13","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hcltechsw","cpe5":"hcl_commerce","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"14275","vulnerable":"1","versionEndIncluding":"9.0.1.14","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hcltechsw","cpe5":"hcl_commerce","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"14275","vulnerable":"1","versionEndIncluding":"9.1.4.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hcltechsw","cpe5":"hcl_commerce","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-14275","ASSIGNER":"psirt@hcl.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"HCL Commerce","version":{"version_data":[{"version_value":"9.0.0.5 through 9.0.0.13"},{"version_value":"9.0.1.0 through 9.0.1.14"},{"version_value":"9.1 through 9.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"\"Denial of Service and Information Disclosure\""}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0086271","url":"https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0086271"}]},"description":{"description_data":[{"lang":"eng","value":"Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations."}]}},"nvd":{"publishedDate":"2021-01-12 15:15:00","lastModifiedDate":"2021-01-14 01:22:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hcltechsw:hcl_commerce:*:*:*:*:*:*:*:*","versionStartIncluding":"9.1","versionEndIncluding":"9.1.4.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hcltechsw:hcl_commerce:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.0.5","versionEndIncluding":"9.0.0.13","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hcltechsw:hcl_commerce:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.1.0","versionEndIncluding":"9.0.1.14","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"14275","Ordinal":"175505","Title":"CVE-2020-14275","CVE":"CVE-2020-14275","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"14275","Ordinal":"1","NoteData":"Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"14275","Ordinal":"2","NoteData":"2021-01-12","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"14275","Ordinal":"3","NoteData":"2021-01-12","Type":"Other","Title":"Modified"}]}}}