Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50346 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 4.3 MEDIUM
HCL DRYiCE MyXalytics is impacted by an information disclosure vulnerability. Certain endpoints within the application disclose detailed file information.
CVE-2023-50348 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 5.3 MEDIUM
HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an attacker with insight into the application, system, etc.
CVE-2023-50345 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 6.1 MEDIUM
HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security threats.
CVE-2023-50350 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 7.5 HIGH
HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt sensitive information.
CVE-2023-45722 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 9.8 CRITICAL
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.  The product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Potential exploits can completely disrupt or take over the application.
CVE-2023-50351 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 9.1 CRITICAL
HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or integrity of data.
CVE-2023-45723 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 9.8 CRITICAL
HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoints permit users to manipulate the path (including the file name) where these files are stored on the server.
CVE-2023-45724 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 9.8 CRITICAL
HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.
CVE-2023-50341 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 7.5 HIGH
HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" vulnerability, which could lead to inadvertent exposure of sensitive information and/or exposing a vulnerable endpoint.
CVE-2023-50342 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 4.3 MEDIUM
HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability.  A user can obtain certain details about another user as a result of improper access control.
CVE-2023-50343 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 6.5 MEDIUM
HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow access to sensitive information about other users.
CVE-2023-50344 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 5.4 MEDIUM
HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files.
CVE-2023-37536 3 Apache, Fedoraproject, Hcltech 3 Xerces-c\+\+, Fedora, Bigfix Platform 2023-12-31 N/A 8.8 HIGH
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
CVE-2023-37520 1 Hcltech 1 Bigfix Platform 2023-12-29 N/A 6.1 MEDIUM
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.
CVE-2023-37519 1 Hcltech 1 Bigfix Platform 2023-12-29 N/A 6.1 MEDIUM
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server. 
CVE-2023-28025 1 Hcltech 1 Bigfix Modern Client Management 2023-12-29 N/A 4.8 MEDIUM
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.
CVE-2023-28022 1 Hcltech 1 Connections 2023-12-20 N/A 6.5 MEDIUM
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
CVE-2023-28017 1 Hcltech 1 Connections 2023-12-12 N/A 5.4 MEDIUM
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
CVE-2023-37533 1 Hcltech 1 Connections 2023-11-16 N/A 6.1 MEDIUM
HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow the attacker to steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
CVE-2023-37511 1 Hcltech 1 Traveler To Do 2023-08-17 N/A 4.3 MEDIUM
If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved.
CVE-2023-37513 1 Hcltech 1 Traveler To Do 2023-08-17 N/A 5.5 MEDIUM
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
CVE-2023-37512 1 Hcltech 1 Traveler Companion 2023-08-17 N/A 5.5 MEDIUM
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
CVE-2023-23342 1 Hcltech 1 Hcl Nomad 2023-08-17 N/A 7.1 HIGH
If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented. 
CVE-2023-23347 1 Hcltech 1 Dryice Iautomate 2023-08-16 N/A 7.1 HIGH
HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
CVE-2023-23346 1 Hcltech 1 Dryice Mycloud 2023-08-15 N/A 7.1 HIGH
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
CVE-2023-37497 1 Hcltech 1 Unica 2023-08-08 N/A 8.8 HIGH
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service.
CVE-2023-37498 1 Hcltech 1 Unica 2023-08-08 N/A 8.8 HIGH
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator.  It is possible that an attacker could potentially escalate their privileges.
CVE-2022-38658 2 Hcltech, Microsoft 2 Bigfix Server Automation, Windows 2023-08-08 N/A 7.5 HIGH
BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data exposed.
CVE-2023-37500 1 Hcltech 1 Unica 2023-08-07 N/A 6.1 MEDIUM
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform.  An attacker could hijack a user's session and perform other attacks.
CVE-2023-37499 1 Hcltech 1 Unica 2023-08-07 N/A 6.1 MEDIUM
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform.  An attacker could hijack a user's session and perform other attacks.
CVE-2023-37501 1 Hcltech 1 Unica 2023-08-07 N/A 6.1 MEDIUM
A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign.  An attacker could hijack a user's session and perform other attacks.
CVE-2023-37496 1 Hcltech 1 Verse 2023-08-04 N/A 5.4 MEDIUM
HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
CVE-2023-28023 1 Hcltech 1 Bigfix Webui 2023-08-01 N/A 6.5 MEDIUM
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 
CVE-2023-28021 1 Hcltech 1 Bigfix Webui 2023-07-27 N/A 7.5 HIGH
The BigFix WebUI uses weak cipher suites.
CVE-2023-28020 1 Hcltech 1 Bigfix Webui 2023-07-27 N/A 6.1 MEDIUM
 URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
CVE-2023-28019 1 Hcltech 1 Bigfix Webui 2023-07-27 N/A 8.8 HIGH
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.
CVE-2021-27760 1 Hcltech 1 Hcl Inotes 2022-07-29 6.0 MEDIUM 5.5 MEDIUM
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.
CVE-2021-27769 1 Hcltech 1 Sametime 2022-07-29 5.0 MEDIUM 5.3 MEDIUM
Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any information that could be used for an attack should be limited whenever possible.
CVE-2021-27772 1 Hcltech 1 Sametime 2022-07-29 4.0 MEDIUM 6.5 MEDIUM
Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it. This could lead to information leakage where confidential information discussed in private groups is read by other users without the users knowledge.
CVE-2022-27544 1 Hcltech 1 Bigfix Platform 2022-07-27 N/A 6.5 MEDIUM
BigFix Web Reports authorized users may see SMTP credentials in clear text.
CVE-2022-27545 1 Hcltech 1 Bigfix Platform 2022-07-27 N/A 5.4 MEDIUM
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
CVE-2020-14263 1 Hcltech 1 Traveler Companion 2022-07-12 2.1 LOW 3.9 LOW
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"
CVE-2021-27786 1 Hcltech 1 Onetest Server 2022-06-16 6.8 MEDIUM 9.8 CRITICAL
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.
CVE-2021-27778 1 Hcltech 1 Traveler 2022-06-08 3.5 LOW 4.8 MEDIUM
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.
CVE-2021-27779 1 Hcltech 1 Versionvault Express 2022-06-08 6.4 MEDIUM 9.1 CRITICAL
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
CVE-2021-27781 1 Hcltech 2 Bigfix Mobile, Modern Client Management 2022-06-08 3.5 LOW 4.8 MEDIUM
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
CVE-2021-27780 1 Hcltech 2 Bigfix Mobile, Modern Client Management 2022-06-08 5.0 MEDIUM 5.3 MEDIUM
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
CVE-2021-27783 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2022-06-07 4.0 MEDIUM 6.5 MEDIUM
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
CVE-2020-4107 1 Hcltech 1 Domino 2022-06-02 4.6 MEDIUM 7.8 HIGH
HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure.
CVE-2021-27777 1 Hcltech 1 Unica 2022-05-25 5.0 MEDIUM 7.5 HIGH
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.