Hcltech
hcltech
427 CVEs • 100 products
Products (100)
Click to collapseToggle
Products (100)
Click to collapse
CVEs (427)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
|
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. If the session identifier can be discovered, it could be...Show more |
HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that can be executed by the server or by a user's web browser.
|
An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.
|
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechan...Show more |
3Apache FedoraprojectHcltech3Bigfix Platform FedoraXerces C++Jun 17, 2026 Oct 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. |
1Hcltech 1Bigfix Insights For Vulnerability Remediation Jun 17, 2026 Oct 11, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.
|
1Hcltech 1Bigfix Insights For Vulnerability Remediation Jun 17, 2026 Oct 11, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.
|
Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.
|
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.
|
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
|
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
|
If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved.
|
If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented.
|
HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
|
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
|
A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign. An attacker could hijack a user's session and perform other attacks.
|
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform. An attacker could hijack a user's session and perform other attacks.
|
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform. An attacker could hijack a user's session and perform other attacks.
|
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It is possible that an attacker could potentially escalate their privileges.
|