HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0107512 | vendor advisory |