CVE-2023-37503: Hcltech Hcl Compass

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.

Affected products

  • Hcltech Hcl Compass: from 2.0.0, up to and including 2.0.3; from 2.2.0, before 2.2.3 (fixed in 2.2.3); version 2.1.0 only

Published 2023-10-19. Last modified 2026-06-17.