← Back

Hcltech

hcltech

427 CVEs • 100 products

Products (100)

Click to collapse
Toggle
Aion
aion
Connections
connections
Domino
domino
Unica
unica
Sametime
sametime
Dfxanalytics
dfxanalytics
Notes
notes
Hcl Leap
hcl_leap
Bigfix Mobile
bigfix_mobile
Domino Leap
domino_leap
Appscan
appscan
Bigfix Webui
bigfix_webui
Hcl Inotes
hcl_inotes
Traveler
traveler
Icontrol
icontrol
Verse
verse
Hcl Compass
hcl_compass
Dryice Aex
dryice_aex
Bigfix Saas
bigfix_saas
Mycloud
mycloud
Dfx Server
dfx_server
Hcl Nomad
hcl_nomad
Hcl Sx
hcl_sx
Hcl Domino
hcl_domino
Hcl Sametime
hcl_sametime
Dragon
dragon
Onetest Server
onetest_server
Commerce
commerce
Myxalytics
myxalytics
Campaign
campaign
Interact
interact
Unica Journey
unica_journey
Unica Plan
unica_plan
Unica Campaign
unica_campaign
Unica Interact
unica_interact
Zie For Web
zie_for_web
Legacy Ivr
legacy_ivr

CVEs (427)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
1Connections
Jun 17, 2026
Mar 5, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute...Show more
The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.Show less
1Hcltech
1Self Service Application
Jun 17, 2026
Feb 28, 2020
N/A· v4
8.4 HIGH· v3
6.0 MEDIUM· v2
BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Running Message or Post Message HTML.
1Hcltech
1Appscan
Jun 17, 2026
Feb 14, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.
1Hcltech
1Appscan Source
Jun 17, 2026
Dec 18, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.
1Hcltech
1Traveler
Jun 17, 2026
Oct 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem...Show more
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message that includes the entered file name. If the file name is not escaped in the returned error page, it could expose a cross-site scripting (XSS) vulnerability.Show less
1Hcltech
1Appscan Source
Jun 17, 2026
Sep 25, 2019
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to...Show more
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to open it. When the victim imports the .ozasmt file in AppScan Source, the content of any file in the local file system (to which the victim as read access) can be exfiltrated to a remote listener under the attacker's control. The product does not disable external XML Entity Processing, which can lead to information disclosure and denial of services attacks.Show less
1Hcltech
1Legacy Ivr Firmware
Nov 21, 2024
May 30, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio signals; based on the frequency, certain commands and functions are process...Show more
A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio signals; based on the frequency, certain commands and functions are processed. Since these frequencies are accepted within a phone call, an attacker can record these frequencies and use them for service activations. This is a request-forgery issue when the required series of DTMF signals for a service activation is predictable (e.g., the IVR system does not speak a nonce to the caller). In this case, the IVR system accepts an activation request from a less-secure channel (any loudspeaker in the caller's physical environment) without verifying that the request was intended (it matches a nonce sent over a more-secure channel to the caller's earpiece).Show less