← Back

Hcltech

hcltech

427 CVEs • 100 products

Products (100)

Click to collapse
Toggle
Aion
aion
Connections
connections
Domino
domino
Unica
unica
Sametime
sametime
Dfxanalytics
dfxanalytics
Notes
notes
Hcl Leap
hcl_leap
Bigfix Mobile
bigfix_mobile
Domino Leap
domino_leap
Appscan
appscan
Bigfix Webui
bigfix_webui
Hcl Inotes
hcl_inotes
Traveler
traveler
Icontrol
icontrol
Verse
verse
Hcl Compass
hcl_compass
Dryice Aex
dryice_aex
Bigfix Saas
bigfix_saas
Mycloud
mycloud
Dfx Server
dfx_server
Hcl Nomad
hcl_nomad
Hcl Sx
hcl_sx
Hcl Domino
hcl_domino
Hcl Sametime
hcl_sametime
Dragon
dragon
Onetest Server
onetest_server
Commerce
commerce
Myxalytics
myxalytics
Campaign
campaign
Interact
interact
Unica Journey
unica_journey
Unica Plan
unica_plan
Unica Campaign
unica_campaign
Unica Interact
unica_interact
Zie For Web
zie_for_web
Legacy Ivr
legacy_ivr

CVEs (427)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
1Unica
Jun 17, 2026
Aug 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the...Show more
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service. Show less
1Hcltech
1Verse
Jun 17, 2026
Aug 1, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session to...Show more
HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information. Show less
1Hcltech
1Bigfix Mobile
Jun 17, 2026
Jul 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.
1Hcltech
1Bigfix Mobile
Jun 17, 2026
Jul 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.
1Hcltech
1Verse
Jun 17, 2026
Jul 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perf...Show more
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information. Show less
1Hcltech
1Bigfix Webui
Jun 17, 2026
Jul 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in...Show more
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network).  Show less
1Hcltech
1Bigfix Webui
Jun 17, 2026
Jul 18, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The BigFix WebUI uses weak cipher suites.
1Hcltech
1Bigfix Webui
Jun 17, 2026
Jul 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
 URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
1Hcltech
1Bigfix Webui
Jun 17, 2026
Jul 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.
1Hcltech
1Bigfix Webui Insights
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
1Hcltech
1Bigfix Osd Bare Metal Server
Jun 17, 2026
Jun 22, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause the OSD Bare Metal Server to perform a redirect to an attacker-controll...Show more
Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause the OSD Bare Metal Server to perform a redirect to an attacker-controlled domain. Show less
1Hcltech
1Bigfix Osd Bare Metal Server
Jun 17, 2026
Jun 22, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.
1Hcltech
1Bigfix Osd Bare Metal Server
Jun 17, 2026
Jun 22, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perfor...Show more
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain. Show less
1Hcltech
1Workload Automation
Jun 17, 2026
Apr 26, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resour...Show more
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. Show less
1Hcltech
1Workload Automation
Jun 17, 2026
Apr 26, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or c...Show more
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. Show less
1Hcltech
1Hcl Compass
Jun 17, 2026
Apr 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious reque...Show more
HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request. Show less
1Hcltech
1Verse
Jun 17, 2026
Mar 10, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability.  By tricking a user into clicking a crafted URL, a remote unauthenticated attacker could execute script in a victim's web browser to perform operati...Show more
HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability.  By tricking a user into clicking a crafted URL, a remote unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information. Show less
1Hcltech
1Hcl Leap
Jun 17, 2026
Feb 12, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.
1Hcltech
1Bigfix Mobile
Jun 17, 2026
Jan 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.
1Hcltech
1Bigfix Server Automation
Jun 17, 2026
Dec 24, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BE...Show more
BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data exposed. Show less