← Back

Hcltech

hcltech

427 CVEs • 100 products

Products (100)

Click to collapse
Toggle
Aion
aion
Connections
connections
Domino
domino
Unica
unica
Sametime
sametime
Dfxanalytics
dfxanalytics
Notes
notes
Hcl Leap
hcl_leap
Bigfix Mobile
bigfix_mobile
Domino Leap
domino_leap
Appscan
appscan
Bigfix Webui
bigfix_webui
Hcl Inotes
hcl_inotes
Traveler
traveler
Icontrol
icontrol
Verse
verse
Hcl Compass
hcl_compass
Dryice Aex
dryice_aex
Bigfix Saas
bigfix_saas
Mycloud
mycloud
Dfx Server
dfx_server
Hcl Nomad
hcl_nomad
Hcl Sx
hcl_sx
Hcl Domino
hcl_domino
Hcl Sametime
hcl_sametime
Dragon
dragon
Onetest Server
onetest_server
Commerce
commerce
Myxalytics
myxalytics
Campaign
campaign
Interact
interact
Unica Journey
unica_journey
Unica Plan
unica_plan
Unica Campaign
unica_campaign
Unica Interact
unica_interact
Zie For Web
zie_for_web
Legacy Ivr
legacy_ivr

CVEs (427)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
2Domino
Hcl Inotes
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
1Hcltech
2Domino
Hcl Inotes
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.4 HIGH· v3
N/A· v2
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
1Hcltech
2Domino
Hcl Inotes
Jun 17, 2026
Aug 29, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability...Show more
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.Show less
1Hcltech
1Bigfix Platform
Jun 17, 2026
Jul 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
1Hcltech
1Bigfix Platform
Jun 17, 2026
Jul 19, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
BigFix Web Reports authorized users may see SMTP credentials in clear text.
1Hcltech
1Onetest Server
Jun 17, 2026
Jun 9, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines t...Show more
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.Show less
1Hcltech
1Traveler
Jun 17, 2026
Jun 1, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerabil...Show more
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.Show less
1Hcltech
2Bigfix Mobile
Modern Client Management
Jun 17, 2026
May 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
1Hcltech
2Bigfix Mobile
Modern Client Management
Jun 17, 2026
May 27, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
1Hcltech
2Bigfix Mobile
Bigfix Modern Client Management
Jun 17, 2026
May 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
1Hcltech
1Versionvault Express
Jun 17, 2026
May 25, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
1Hcltech
1Domino
Jun 17, 2026
May 19, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or...Show more
HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure.Show less
1Hcltech
1Unica
Jun 17, 2026
May 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content a...Show more
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.Show less
1Hcltech
1Sametime
Jun 17, 2026
May 12, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
This vulnerability allows users to execute a clickjacking attack in the meeting's chat.
1Hcltech
1Sametime
Jun 17, 2026
May 12, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the cont...Show more
Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it. This could lead to information leakage where confidential information discussed in private groups is read by other users without the users knowledge.Show less
1Hcltech
1Sametime
Jun 17, 2026
May 12, 2022
N/A· v4
7.6 HIGH· v3
6.5 MEDIUM· v2
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containin...Show more
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.Show less
1Hcltech
1Sametime
Jun 17, 2026
May 12, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can spe...Show more
The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can specify an external URL where the online meeting will take place.Show less
1Hcltech
1Sametime
Jun 17, 2026
May 12, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to o...Show more
Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any information that could be used for an attack should be limited whenever possible.Show less
1Hcltech
1Verse
Jun 17, 2026
May 12, 2022
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's netw...Show more
Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in 'transparent' mode while a certificate with an invalid hostname was active. The Android application was found to have hostname verification issues during the server setup and login flows; however, the application did not process requests post-login.Show less
1Hcltech
1Bigfix Platform
Jun 17, 2026
May 6, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updati...Show more
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.Show less