← Back

Hcltech

hcltech

427 CVEs • 100 products

Products (100)

Click to collapse
Toggle
Aion
aion
Connections
connections
Domino
domino
Unica
unica
Sametime
sametime
Dfxanalytics
dfxanalytics
Notes
notes
Hcl Leap
hcl_leap
Bigfix Mobile
bigfix_mobile
Domino Leap
domino_leap
Appscan
appscan
Bigfix Webui
bigfix_webui
Hcl Inotes
hcl_inotes
Traveler
traveler
Icontrol
icontrol
Verse
verse
Hcl Compass
hcl_compass
Dryice Aex
dryice_aex
Bigfix Saas
bigfix_saas
Mycloud
mycloud
Dfx Server
dfx_server
Hcl Nomad
hcl_nomad
Hcl Sx
hcl_sx
Hcl Domino
hcl_domino
Hcl Sametime
hcl_sametime
Dragon
dragon
Onetest Server
onetest_server
Commerce
commerce
Myxalytics
myxalytics
Campaign
campaign
Interact
interact
Unica Journey
unica_journey
Unica Plan
unica_plan
Unica Campaign
unica_campaign
Unica Interact
unica_interact
Zie For Web
zie_for_web
Legacy Ivr
legacy_ivr

CVEs (427)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
1Hcl Compass
Jun 17, 2026
Oct 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
1Hcltech
1Hcl Compass
Jun 17, 2026
Oct 19, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be...Show more
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user. Show less
1Hcltech
1Hcl Compass
Jun 17, 2026
Oct 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that can be executed by the server or by a user's web browser.
1Hcltech
1Appscan Presence
Jun 17, 2026
Oct 17, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.
1Hcltech
1Digital Experience
Jun 17, 2026
Oct 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechan...Show more
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site). Show less
3Apache
FedoraprojectHcltech
3Bigfix Platform
FedoraXerces C++
Jun 17, 2026
Oct 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
1Hcltech
1Bigfix Insights For Vulnerability Remediation
Jun 17, 2026
Oct 11, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.
1Hcltech
1Bigfix Insights For Vulnerability Remediation
Jun 17, 2026
Oct 11, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.
1Hcltech
1Bigfix Patch Management
Jun 17, 2026
Oct 11, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.
1Hcltech
1Domino
Jun 17, 2026
Sep 8, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.
1Hcltech
1Traveler To Do
Jun 17, 2026
Aug 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
1Hcltech
1Traveler Companion
Jun 17, 2026
Aug 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
1Hcltech
1Traveler To Do
Jun 17, 2026
Aug 11, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved.
1Hcltech
1Hcl Nomad
Jun 17, 2026
Aug 10, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented. 
1Hcltech
1Dryice Iautomate
Jun 17, 2026
Aug 9, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
1Hcltech
1Dryice Mycloud
Jun 17, 2026
Aug 9, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
1Hcltech
1Unica
Jun 17, 2026
Aug 3, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign.  An attacker could hijack a user's session and perform other attacks.
1Hcltech
1Unica
Jun 17, 2026
Aug 3, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform.  An attacker could hijack a user's session and perform other attacks.
1Hcltech
1Unica
Jun 17, 2026
Aug 3, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform.  An attacker could hijack a user's session and perform other attacks.
1Hcltech
1Unica
Jun 17, 2026
Aug 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator.  It is possible that an attacker could potentially escalate their privileges.