Skip to main content

Vendor archive

hcltech CVEs

Beta · best-effort

427 CVEs tagged to vendor hcltech18 Critical, 74 High, 205 Medium, 130 Low, 0 Unrated.

CVE-2024-42179

Published Jan 12, 2025

HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version.

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42175

Published Jan 11, 2025

HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. This can lead to security vulne…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42174

Published Jan 11, 2025

HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration of application users, and therefore compile a list of valid…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42173

Published Jan 11, 2025

HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-forc…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42172

Published Jan 11, 2025

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system contr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42171

Published Jan 11, 2025

HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42170

Published Jan 11, 2025

HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42169

Published Jan 11, 2025

HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user should be allowed to access s…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42168

Published Jan 11, 2025

HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, and then induce the application…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42188

Published Nov 14, 2024

HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30133

Published Nov 12, 2024

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30142

Published Nov 7, 2024

HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized acc…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30141

Published Nov 7, 2024

HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose inf…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30140

Published Nov 7, 2024

HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provid…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30106

Published Oct 28, 2024

HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive informatio…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-50355

Published Oct 23, 2024

HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30124

Published Oct 23, 2024

HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30122

Published Oct 23, 2024

HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less sec…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30117

Published Oct 14, 2024

A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30118

Published Oct 9, 2024

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly ha…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30132

Published Oct 1, 2024

HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-23586

Published Sep 27, 2024

HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30128

Published Sep 25, 2024

HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort
Showing 201-225 of 427 CVEsPage 9 of 18