Filtered by vendor Hcltech Subscriptions
Total 189 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-28025 1 Hcltech 1 Bigfix Modern Client Management 2024-08-02 6.6 Medium
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.
CVE-2023-28006 1 Hcltech 1 Bigfix Osd Bare Metal Server 2024-08-02 7 High
The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.
CVE-2023-28017 1 Hcltech 1 Connections 2024-08-02 5.4 Medium
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
CVE-2023-28022 1 Hcltech 1 Connections 2024-08-02 3.5 Low
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
CVE-2023-28008 1 Hcltech 1 Workload Automation 2024-08-02 7.1 High
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
CVE-2023-28009 1 Hcltech 1 Workload Automation 2024-08-02 6.5 Medium
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
CVE-2023-23343 1 Hcltech 1 Bigfix Osd Bare Metal Server 2024-08-02 2.4 Low
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain.
CVE-2024-30107 1 Hcltech 1 Connections 2024-08-02 3.5 Low
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.
CVE-2024-23553 1 Hcltech 1 Bigfix Platform 2024-08-01 3 Low
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.