← Back

Hcltech

hcltech

455 CVEs • 102 products

Products (102)

Click to collapse
Toggle
Aion
aion
Connections
connections
Domino
domino
Unica
unica
Sametime
sametime
Dfxanalytics
dfxanalytics
Icontrol
icontrol
Notes
notes
Hcl Leap
hcl_leap
Bigfix Mobile
bigfix_mobile
Domino Leap
domino_leap
Appscan
appscan
Bigfix Webui
bigfix_webui
Hcl Inotes
hcl_inotes
Traveler
traveler
Verse
verse
Devops Plan
devops_plan
Hcl Compass
hcl_compass
Dryice Aex
dryice_aex
Bigfix Saas
bigfix_saas
Mycloud
mycloud
Dfx Server
dfx_server
Devops Loop
devops_loop
Hcl Nomad
hcl_nomad
Hcl Sx
hcl_sx
Hcl Domino
hcl_domino
Hcl Sametime
hcl_sametime
Dragon
dragon
Onetest Server
onetest_server
Commerce
commerce
Myxalytics
myxalytics
Campaign
campaign
Interact
interact
Unica Journey
unica_journey
Unica Plan
unica_plan
Unica Campaign
unica_campaign
Unica Interact
unica_interact

CVEs (455)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
1Hcl Inotes
Jun 17, 2026
Dec 1, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available...Show more
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later.Show less
1Hcltech
1Hcl Domino
Jun 17, 2026
Nov 30, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from t...Show more
HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and 11.0.1 FP1 and later.Show less
1Hcltech
1Notes
Jun 17, 2026
Nov 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email messa...Show more
HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the client. Versions 9, 10 and 11 are affected.Show less
1Hcltech
1Domino
Jun 17, 2026
Nov 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the ability to crash the server. Versions previous to release 9.0.1 FP10 IF...Show more
HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the ability to crash the server. Versions previous to release 9.0.1 FP10 IF6 and release 10.0.1 are affected.Show less
1Hcltech
1Domino
Jun 17, 2026
Nov 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email mess...Show more
HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the server. Versions previous to releases 9.0.1 FP10 IF6, 10.0.1 FP5 and 11.0.1 are affected.Show less
1Hcltech
1Notes
Jun 17, 2026
Nov 5, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of t...Show more
In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an attacker resulting in a buffer overflow. This could enable an attacker to crash HCL Notes or execute attacker-controlled code on the client.Show less
1Hcltech
1Notes
Jun 17, 2026
Nov 5, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victi...Show more
HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.Show less
1Hcltech
1Hcl Digital Experience
Jun 17, 2026
Nov 5, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some d...Show more
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).Show less
1Hcltech
1Appscan
Jun 17, 2026
Oct 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
1Hcltech
1Appscan
Jun 17, 2026
Oct 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
1Hcltech
1Digital Experience
Jun 17, 2026
Oct 1, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.
1Hcltech
1Bigfix Webui
Jun 17, 2026
Jul 17, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest...Show more
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855&sys_kb_id=971d99ed1b8ed01c086dcbfc0a4bcb6a.Show less
1Hcltech
1Marketing Campaign
Jun 17, 2026
Jul 17, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system....Show more
"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "Show less
1Hcltech
1Marketing Campaign
Jun 17, 2026
Jul 17, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
"HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."
1Hcltech
1Bigfix Platform
Jun 17, 2026
Jul 16, 2020
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These creden...Show more
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."Show less
1Hcltech
1Appscan
Jun 17, 2026
Jul 7, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
1Hcltech
1Appscan
Jun 17, 2026
Jul 7, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
1Hcltech
1Domino
Nov 21, 2024
Jul 1, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An...Show more
"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions."Show less
1Hcltech
1Notes
Jun 17, 2026
Jun 26, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being le...Show more
HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and 11 are affected.Show less
1Hcltech
1Hcl Digital Experience
Jun 17, 2026
Jun 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
"HCL Digital Experience is susceptible to Server Side Request Forgery."