Lucene search

K

HCL Software Security Vulnerabilities

cve
cve

CVE-2024-30119

HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during...

3.7CVSS

4.2AI Score

0.0004EPSS

2024-06-14 10:15 PM
22
cve
cve

CVE-2023-37541

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain...

3.5CVSS

7AI Score

0.0004EPSS

2024-06-25 03:15 PM
3
cve
cve

CVE-2024-23560

HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource...

4.4CVSS

6.8AI Score

0.0004EPSS

2024-04-15 08:15 PM
25
cve
cve

CVE-2024-30112

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials...

5.4CVSS

5.8AI Score

0.0004EPSS

2024-06-25 10:15 PM
5
cve
cve

CVE-2024-30120

HCL DRYiCE Optibot Reset Station is impacted by an Unused Parameter in the web...

2.9CVSS

3.9AI Score

0.0004EPSS

2024-06-14 10:15 PM
22
cve
cve

CVE-2024-23554

Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution...

5.7CVSS

7.6AI Score

0.0004EPSS

2024-05-18 12:15 AM
31
cve
cve

CVE-2023-45707

HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional...

4.4CVSS

5.1AI Score

0.0004EPSS

2024-06-08 03:15 PM
21
cve
cve

CVE-2023-45696

Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the...

4CVSS

4.3AI Score

0.0004EPSS

2024-02-10 03:15 AM
13
cve
cve

CVE-2024-23580

HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted...

6.5CVSS

6.8AI Score

0.0004EPSS

2024-05-28 10:15 PM
3
cve
cve

CVE-2023-28018

HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected...

5.5CVSS

5.5AI Score

0.0004EPSS

2024-02-12 11:15 PM
17
cve
cve

CVE-2023-37495

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the hashed value to determine...

5.9CVSS

5.6AI Score

0.0004EPSS

2024-02-29 01:40 AM
19
cve
cve

CVE-2023-37529

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerability as identified in...

3CVSS

3.7AI Score

0.0004EPSS

2024-02-29 01:40 AM
7
cve
cve

CVE-2023-37530

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored...

3CVSS

3.7AI Score

0.0004EPSS

2024-02-29 01:40 AM
7
cve
cve

CVE-2023-45705

An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration...

3.5CVSS

7AI Score

0.0004EPSS

2024-03-28 03:15 PM
27
cve
cve

CVE-2024-23556

SSL/TLS Renegotiation functionality potentially leading to DoS attack...

5.9CVSS

6.8AI Score

0.0004EPSS

2024-05-18 12:15 AM
32
cve
cve

CVE-2024-23558

HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the...

6.3CVSS

6.6AI Score

0.0004EPSS

2024-04-15 09:15 PM
22
cve
cve

CVE-2023-37539

The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user...

8.4CVSS

5.2AI Score

0.0004EPSS

2024-06-06 11:15 PM
27
cve
cve

CVE-2023-37531

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged...

3.3CVSS

4AI Score

0.0004EPSS

2024-02-29 01:40 AM
8
cve
cve

CVE-2023-37526

HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which could potentially allow unauthorized access to the application resources from any web domain and enable cache poisoning...

6.5CVSS

6.7AI Score

0.0004EPSS

2024-05-14 01:20 PM
8
cve
cve

CVE-2023-45718

Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their...

3.9CVSS

4.3AI Score

0.0004EPSS

2024-02-09 10:15 PM
15
cve
cve

CVE-2024-23579

HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover some or all encrypted...

6.5CVSS

6.8AI Score

0.0004EPSS

2024-05-28 10:15 PM
1
cve
cve

CVE-2024-23583

An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows...

6.7CVSS

6.8AI Score

0.0004EPSS

2024-05-17 11:15 PM
25
cve
cve

CVE-2024-30107

HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain...

3.5CVSS

6.3AI Score

0.0004EPSS

2024-04-18 09:15 PM
28
cve
cve

CVE-2023-45706

An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML...

2CVSS

6.1AI Score

0.0004EPSS

2024-03-28 03:15 PM
32
cve
cve

CVE-2023-37523

Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's...

9.8CVSS

9.3AI Score

0.001EPSS

2024-01-16 06:15 PM
17
cve
cve

CVE-2024-23550

HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows...

6.2CVSS

5.3AI Score

0.0004EPSS

2024-02-03 06:15 AM
14
cve
cve

CVE-2024-23576

Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative...

7.1CVSS

6.9AI Score

0.0004EPSS

2024-05-14 02:59 PM
18
cve
cve

CVE-2024-23551

Database scanning using username and password stores the credentials in plaintext or encoded format within files at the endpoint. This has been identified as a significant security risk. This will lead to exposure of sensitive information for unauthorized access, potentially leading to severe...

6.5CVSS

6.6AI Score

0.0004EPSS

2024-05-07 10:15 PM
33
cve
cve

CVE-2024-23557

HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force...

3.5CVSS

6.7AI Score

0.0004EPSS

2024-04-18 07:15 PM
27
cve
cve

CVE-2023-50347

HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run arbitrary SQL commands including changing system...

3.7CVSS

7.9AI Score

0.0004EPSS

2024-04-10 02:15 AM
48
cve
cve

CVE-2024-23561

HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive...

4.3CVSS

6.2AI Score

0.0004EPSS

2024-04-15 09:15 PM
27
cve
cve

CVE-2024-23559

HCL DevOps Deploy / Launch is generating an obsolete HTTP...

6.1CVSS

6.9AI Score

0.0004EPSS

2024-04-15 06:15 PM
27
cve
cve

CVE-2024-23584

The NMAP Importer service​ may expose data store credentials to authorized users of the Windows...

6.6CVSS

6.8AI Score

0.0004EPSS

2024-04-08 11:15 PM
27
cve
cve

CVE-2024-23540

The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static...

5.3CVSS

6.6AI Score

0.0004EPSS

2024-04-03 05:15 PM
27
cve
cve

CVE-2023-45715

The console may experience a service interruption when processing file names with invalid...

3.5CVSS

6.8AI Score

0.0004EPSS

2024-03-28 03:15 PM
33
cve
cve

CVE-2023-45716

Sametime is impacted by sensitive information passed in...

4.1CVSS

4.4AI Score

0.0004EPSS

2024-02-09 10:15 PM
16
cve
cve

CVE-2023-37540

Sametime Connect desktop chat client includes, but does not use or require, the use of an Eclipse feature called Secure Storage. Using this Eclipse feature to store sensitive data can lead to exposure of that...

3.9CVSS

4.3AI Score

0.0004EPSS

2024-02-23 07:15 AM
53
cve
cve

CVE-2023-50349

Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the...

8.8CVSS

8.7AI Score

0.001EPSS

2024-02-09 09:15 PM
12
cve
cve

CVE-2023-37528

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save...

6.5CVSS

6.1AI Score

0.001EPSS

2024-02-03 06:15 AM
9
cve
cve

CVE-2023-45698

Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking...

4.8CVSS

5.1AI Score

0.0004EPSS

2024-02-10 04:15 AM
16
cve
cve

CVE-2024-23553

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header...

5.4CVSS

5.2AI Score

0.0004EPSS

2024-02-02 09:15 PM
18
cve
cve

CVE-2023-37527

A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web...

6.1CVSS

6AI Score

0.001EPSS

2024-02-02 07:15 PM
9
cve
cve

CVE-2023-37518

HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running...

8.8CVSS

8.8AI Score

0.0005EPSS

2024-01-30 04:15 PM
21
cve
cve

CVE-2023-37522

HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's...

9.8CVSS

9.4AI Score

0.001EPSS

2024-01-16 04:15 PM
17
cve
cve

CVE-2023-37521

HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker to execute a malicious...

5.3CVSS

5.3AI Score

0.0005EPSS

2024-01-16 04:15 PM
11
cve
cve

CVE-2023-50348

HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an attacker with insight into the application, system,...

5.3CVSS

5.3AI Score

0.0005EPSS

2024-01-03 02:15 AM
14
cve
cve

CVE-2023-45724

HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user...

9.8CVSS

9.4AI Score

0.001EPSS

2024-01-03 03:15 AM
15
cve
cve

CVE-2023-45723

HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability. Certain endpoints permit users to manipulate the path (including the file name) where these files are stored on the...

9.8CVSS

9.3AI Score

0.001EPSS

2024-01-03 03:15 AM
16
cve
cve

CVE-2023-50346

HCL DRYiCE MyXalytics is impacted by an information disclosure vulnerability. Certain endpoints within the application disclose detailed file...

4.3CVSS

4.5AI Score

0.0004EPSS

2024-01-03 02:15 AM
15
cve
cve

CVE-2023-50345

HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security...

6.1CVSS

6.2AI Score

0.0005EPSS

2024-01-03 02:15 AM
15
Total number of security vulnerabilities173