Filtered by vendor Hcltech
Subscriptions
Total
189 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-27757 | 1 Hcltech | 1 Bigfix Insights | 2024-11-21 | 7.5 High |
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive information." | ||||
CVE-2021-27756 | 1 Hcltech | 1 Bigfix Compliance | 2024-11-21 | 7.5 High |
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it." | ||||
CVE-2021-27755 | 1 Hcltech | 1 Hcl Sametime | 2024-11-21 | 5.5 Medium |
"Sametime Android potential path traversal vulnerability when using File class" | ||||
CVE-2021-27753 | 1 Hcltech | 1 Hcl Sametime | 2024-11-21 | 5.5 Medium |
"Sametime Android PathTraversal Vulnerability" | ||||
CVE-2020-4129 | 1 Hcltech | 1 Hcl Domino | 2024-11-21 | 5.3 Medium |
HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the LDAP service. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and 11.0.1 FP1 and later. | ||||
CVE-2020-4128 | 1 Hcltech | 1 Domino | 2024-11-21 | 5.3 Medium |
HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the ID Vault service. | ||||
CVE-2020-4127 | 1 Hcltech | 1 Hcl Domino | 2024-11-21 | 6.5 Medium |
HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and 11.0.1 FP1 and later. | ||||
CVE-2020-4126 | 1 Hcltech | 1 Hcl Inotes | 2024-11-21 | 5.9 Medium |
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later. | ||||
CVE-2020-4107 | 1 Hcltech | 1 Domino | 2024-11-21 | 8.8 High |
HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure. | ||||
CVE-2020-4104 | 1 Hcltech | 1 Bigfix Webui | 2024-11-21 | 5.4 Medium |
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855&sys_kb_id=971d99ed1b8ed01c086dcbfc0a4bcb6a. | ||||
CVE-2020-4102 | 1 Hcltech | 1 Notes | 2024-11-21 | 6.7 Medium |
HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Notes or execute attacker-controlled code on the client system. | ||||
CVE-2020-4101 | 1 Hcltech | 1 Hcl Digital Experience | 2024-11-21 | 9.8 Critical |
"HCL Digital Experience is susceptible to Server Side Request Forgery." | ||||
CVE-2020-4099 | 1 Hcltech | 1 Verse | 2024-11-21 | 5.9 Medium |
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app. | ||||
CVE-2020-4097 | 1 Hcltech | 1 Notes | 2024-11-21 | 6.8 Medium |
In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an attacker resulting in a buffer overflow. This could enable an attacker to crash HCL Notes or execute attacker-controlled code on the client. | ||||
CVE-2020-4095 | 1 Hcltech | 1 Bigfix Platform | 2024-11-21 | 6.0 Medium |
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access." | ||||
CVE-2020-4092 | 1 Hcltech | 1 Hcl Nomad | 2024-11-21 | 5.3 Medium |
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can potentially expose sensitive information including but not limited to server names, user IDs and document content." | ||||
CVE-2020-4089 | 1 Hcltech | 1 Notes | 2024-11-21 | 6.5 Medium |
HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and 11 are affected. | ||||
CVE-2020-4085 | 1 Hcltech | 1 Connections | 2024-11-21 | 6.5 Medium |
"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user." | ||||
CVE-2020-4084 | 1 Hcltech | 1 Connections | 2024-11-21 | 5.4 Medium |
HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | ||||
CVE-2020-4083 | 1 Hcltech | 1 Connections | 2024-11-21 | 5.5 Medium |
HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user. |