← Back

Hcltech

hcltech

427 CVEs • 100 products

Products (100)

Click to collapse
Toggle
Aion
aion
Connections
connections
Domino
domino
Unica
unica
Sametime
sametime
Dfxanalytics
dfxanalytics
Notes
notes
Hcl Leap
hcl_leap
Bigfix Mobile
bigfix_mobile
Domino Leap
domino_leap
Appscan
appscan
Bigfix Webui
bigfix_webui
Hcl Inotes
hcl_inotes
Traveler
traveler
Icontrol
icontrol
Verse
verse
Hcl Compass
hcl_compass
Dryice Aex
dryice_aex
Bigfix Saas
bigfix_saas
Mycloud
mycloud
Dfx Server
dfx_server
Hcl Nomad
hcl_nomad
Hcl Sx
hcl_sx
Hcl Domino
hcl_domino
Hcl Sametime
hcl_sametime
Dragon
dragon
Onetest Server
onetest_server
Commerce
commerce
Myxalytics
myxalytics
Campaign
campaign
Interact
interact
Unica Journey
unica_journey
Unica Plan
unica_plan
Unica Campaign
unica_campaign
Unica Interact
unica_interact
Zie For Web
zie_for_web
Legacy Ivr
legacy_ivr

CVEs (427)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
1Appscan
Jun 17, 2026
Oct 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
1Hcltech
1Appscan
Jun 17, 2026
Oct 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
1Hcltech
1Digital Experience
Jun 17, 2026
Oct 1, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.
1Hcltech
1Bigfix Webui
Jun 17, 2026
Jul 17, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest...Show more
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855&sys_kb_id=971d99ed1b8ed01c086dcbfc0a4bcb6a.Show less
1Hcltech
1Marketing Campaign
Jun 17, 2026
Jul 17, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system....Show more
"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "Show less
1Hcltech
1Marketing Campaign
Jun 17, 2026
Jul 17, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
"HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."
1Hcltech
1Bigfix Platform
Jun 17, 2026
Jul 16, 2020
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These creden...Show more
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."Show less
1Hcltech
1Appscan
Jun 17, 2026
Jul 7, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
1Hcltech
1Appscan
Jun 17, 2026
Jul 7, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
1Hcltech
1Domino
Nov 21, 2024
Jul 1, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An...Show more
"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions."Show less
1Hcltech
1Notes
Jun 17, 2026
Jun 26, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being le...Show more
HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and 11 are affected.Show less
1Hcltech
1Hcl Digital Experience
Jun 17, 2026
Jun 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
"HCL Digital Experience is susceptible to Server Side Request Forgery."
1Hcltech
1Hcl Nomad
Jun 17, 2026
May 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encry...Show more
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can potentially expose sensitive information including but not limited to server names, user IDs and document content."Show less
1Hcltech
1Connections
Jun 17, 2026
May 1, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.
1Hcltech
1Connections
Jun 17, 2026
Apr 22, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."
1Hcltech
1Appscan
Jun 17, 2026
Apr 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
1Hcltech
1Appscan
Jun 17, 2026
Apr 7, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
HCL AppScan Standard is vulnerable to excessive authorization attempts
1Hcltech
1Appscan
Jun 17, 2026
Apr 7, 2020
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
1Hcltech
1Connections
Jun 17, 2026
Mar 9, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t...Show more
HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Hcltech
1Connections
Jun 17, 2026
Mar 5, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.