← Back

Hcltech

hcltech

427 CVEs • 100 products

Products (100)

Click to collapse
Toggle
Aion
aion
Connections
connections
Domino
domino
Unica
unica
Sametime
sametime
Dfxanalytics
dfxanalytics
Notes
notes
Hcl Leap
hcl_leap
Bigfix Mobile
bigfix_mobile
Domino Leap
domino_leap
Appscan
appscan
Bigfix Webui
bigfix_webui
Hcl Inotes
hcl_inotes
Traveler
traveler
Icontrol
icontrol
Verse
verse
Hcl Compass
hcl_compass
Dryice Aex
dryice_aex
Bigfix Saas
bigfix_saas
Mycloud
mycloud
Dfx Server
dfx_server
Hcl Nomad
hcl_nomad
Hcl Sx
hcl_sx
Hcl Domino
hcl_domino
Hcl Sametime
hcl_sametime
Dragon
dragon
Onetest Server
onetest_server
Commerce
commerce
Myxalytics
myxalytics
Campaign
campaign
Interact
interact
Unica Journey
unica_journey
Unica Plan
unica_plan
Unica Campaign
unica_campaign
Unica Interact
unica_interact
Zie For Web
zie_for_web
Legacy Ivr
legacy_ivr

CVEs (427)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
1Bigfix Platform
Jun 17, 2026
May 6, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updatin...Show more
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.Show less
1Hcltech
1Bigfix Platform
Jun 17, 2026
May 6, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by upd...Show more
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.Show less
1Hcltech
1Bigfix Webui
Jun 17, 2026
May 6, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)
1Hcltech
1Bigfix Platform
Jun 17, 2026
May 6, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses
1Hcltech
1Bigfix Platform
Jun 17, 2026
May 6, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
1Hcltech
1Hcl Inotes
Jun 17, 2026
May 6, 2022
N/A· v4
5.5 MEDIUM· v3
6.0 MEDIUM· v2
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted m...Show more
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.Show less
1Hcltech
1Bigfix Inventory
Jun 17, 2026
May 6, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP reque...Show more
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.Show less
1Hcltech
1Bigfix Inventory
Jun 17, 2026
May 6, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.
1Hcltech
1Bigfix Compliance
Jun 17, 2026
Mar 4, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."
1Hcltech
1Bigfix Insights
Jun 17, 2026
Mar 4, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers cou...Show more
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive information."Show less
1Hcltech
1Hcl Sametime
Jun 17, 2026
Feb 21, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
"Sametime Android potential path traversal vulnerability when using File class"
1Hcltech
1Hcl Sametime
Jun 17, 2026
Feb 21, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
"Sametime Android PathTraversal Vulnerability"
1Hcltech
1Traveler Companion
Jun 17, 2026
Oct 25, 2021
N/A· v4
3.9 LOW· v3
2.1 LOW· v2
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"
1Hcltech
1Traveler Companion
Jun 17, 2026
Oct 21, 2021
N/A· v4
3.9 LOW· v3
2.1 LOW· v2
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"
1Hcltech
1Digital Experience
Jun 17, 2026
Feb 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).
1Hcltech
1Digital Experience
Jun 17, 2026
Feb 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditional on-premise instal...Show more
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditional on-premise installations.Show less
1Hcltech
1Digital Experience
Jun 17, 2026
Feb 2, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.
1Hcltech
1Domino
Jun 17, 2026
Dec 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino serve...Show more
HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino server.Show less
1Hcltech
1Domino
Jun 17, 2026
Dec 22, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthenticated attacker could exploit this vulnerability to obtain information...Show more
HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthenticated attacker could exploit this vulnerability to obtain information about the XPages software running on the Domino server.Show less
2Hcltech
Hcltechsw
2Hcl Inotes
Hcl Inotes
Jun 17, 2026
Dec 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive inf...Show more
HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack.Show less