go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Learning Digital Orca HCM - Improper Authentication

TVN ID TVN-202502004
CVE ID CVE-2025-1387
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Orca HCM before version 11.0
Description Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.
Solution For standard user, please update to version 11.0 or later.
For customized user, please contact the vendor for updates.
Credit Security member
Public Date 2025-02-17
Top