Skip to main content

Vendor archive

hcltech CVEs

Beta · best-effort

427 CVEs tagged to vendor hcltech18 Critical, 74 High, 205 Medium, 130 Low, 0 Unrated.

CVE-2024-30130

Published Jul 19, 2024

HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30126

Published Jul 18, 2024

HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or i…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30125

Published Jul 18, 2024

HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23562

Published Jul 8, 2024

A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23588

Published Jul 5, 2024

HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30135

Published Jun 28, 2024

HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30111

Published Jun 28, 2024

HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted device due to which malicious…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30110

Published Jun 28, 2024

HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into a system which can cause the…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30109

Published Jun 28, 2024

HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layers to trick a user into clickin…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30112

Published Jun 25, 2024

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user wh…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37541

Published Jun 25, 2024

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37539

Published Jun 6, 2024

The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23556

Published May 18, 2024

SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23554

Published May 18, 2024

Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30107

Published Apr 18, 2024

HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-23557

Published Apr 18, 2024

HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force atta…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-50347

Published Apr 10, 2024

HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run ar…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-45706

Published Mar 28, 2024

An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-45705

Published Mar 28, 2024

An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37531

Published Feb 29, 2024

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form fiel…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37530

Published Feb 29, 2024

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage t…

CVSS 3.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37529

Published Feb 29, 2024

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage t…

CVSS 3.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37495

Published Feb 29, 2024

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured us…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 226-250 of 427 CVEsPage 10 of 18