CVE-2023-37532: Hcltech Commerce

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.

Affected products

  • Hcltech Commerce: from 9.1.8, up to and including 9.1.13.2

Published 2023-10-23. Last modified 2026-06-17.