Researchers disclosed multiple vulnerabilities in HCL WebSphere Portal, now HCL Digital Experience, including CVE-2021-27748, that could allow unauthenticated attackers to make arbitrary server-side requests and read full HTTP responses. Default proxy routes trusted selected IBM domains, but a Lotus Domino open redirect on redbooks.ibm.com could reportedly be chained to reach arbitrary targets, including internal services and cloud metadata endpoints. Additional PA_WCM_Authoring_UI and Quickr Document Picker endpoints allegedly enabled pre-authentication full-read SSRF, with the former supporting multiple methods, request bodies, and selected headers.
The researchers also reported a post-authentication flaw in Script Application ZIP imports: directory traversal during extraction could enable arbitrary file upload and, on affected Linux deployments, potential root remote code execution after reboot. Assetnote said it submitted six reports to HCL Technologies beginning September 2021, but reported that the vendor had neither reproduced the findings nor supplied remediation or CVE assignments before the researchers' 90-day disclosure deadline. Organizations running WebSphere Portal/Digital Experience should identify exposed instances, restrict access to proxy and administration endpoints, and validate vendor patch status and mitigations.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Assetnote stated that its 90-day disclosure period ended without HCL providing remediation or assigning CVEs for the reported issues.
Assetnote reported receiving no further response from HCL Technologies after this date, despite reminders about the approaching 90-day disclosure deadline.
HCL Technologies told the researchers it could not reproduce the reported WebSphere Portal vulnerabilities and said CVEs would not be filed until remediation steps were available.
HCL Technologies initially responded that the vulnerability reports had been submitted to its product teams.
Assetnote Security Research Team submitted six SSRF and post-authentication RCE reports to HCL Technologies.
HCL published a security bulletin stating that multiple vulnerabilities affect HCL Digital Experience and identifying CVE-2021-27748 and CVE-2021-3765.
Assetnote researchers identified multiple unauthenticated full-read SSRF paths in HCL WebSphere Portal/Digital Experience, including redirect-chain and direct proxy routes, plus a post-authentication ZIP extraction directory-traversal issue that could enable arbitrary file writes and potential root RCE after reboot on affected Linux systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
slcyber.io
Open sourceslcyber.io
Open sourceblog.assetnote.io
Open sourcesupport.hcltechsw.com
Open sourcefirst.org
Open sourcefirst.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.