Filtered by vendor Hcltech
Subscriptions
Total
189 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-28025 | 1 Hcltech | 1 Bigfix Modern Client Management | 2024-08-02 | 6.6 Medium |
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage. | ||||
CVE-2023-28006 | 1 Hcltech | 1 Bigfix Osd Bare Metal Server | 2024-08-02 | 7 High |
The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure. | ||||
CVE-2023-28017 | 1 Hcltech | 1 Connections | 2024-08-02 | 5.4 Medium |
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise a user's account then launch other attacks. | ||||
CVE-2023-28022 | 1 Hcltech | 1 Connections | 2024-08-02 | 3.5 Low |
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data. | ||||
CVE-2023-28008 | 1 Hcltech | 1 Workload Automation | 2024-08-02 | 7.1 High |
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | ||||
CVE-2023-28009 | 1 Hcltech | 1 Workload Automation | 2024-08-02 | 6.5 Medium |
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | ||||
CVE-2023-23343 | 1 Hcltech | 1 Bigfix Osd Bare Metal Server | 2024-08-02 | 2.4 Low |
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain. | ||||
CVE-2024-30107 | 1 Hcltech | 1 Connections | 2024-08-02 | 3.5 Low |
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios. | ||||
CVE-2024-23553 | 1 Hcltech | 1 Bigfix Platform | 2024-08-01 | 3 Low |
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute. |