Filtered by vendor Hcltech Subscriptions
Total 189 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-27757 1 Hcltech 1 Bigfix Insights 2024-11-21 7.5 High
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive information."
CVE-2021-27756 1 Hcltech 1 Bigfix Compliance 2024-11-21 7.5 High
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."
CVE-2021-27755 1 Hcltech 1 Hcl Sametime 2024-11-21 5.5 Medium
"Sametime Android potential path traversal vulnerability when using File class"
CVE-2021-27753 1 Hcltech 1 Hcl Sametime 2024-11-21 5.5 Medium
"Sametime Android PathTraversal Vulnerability"
CVE-2020-4129 1 Hcltech 1 Hcl Domino 2024-11-21 5.3 Medium
HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the LDAP service. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and 11.0.1 FP1 and later.
CVE-2020-4128 1 Hcltech 1 Domino 2024-11-21 5.3 Medium
HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the ID Vault service.
CVE-2020-4127 1 Hcltech 1 Hcl Domino 2024-11-21 6.5 Medium
HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and 11.0.1 FP1 and later.
CVE-2020-4126 1 Hcltech 1 Hcl Inotes 2024-11-21 5.9 Medium
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later.
CVE-2020-4107 1 Hcltech 1 Domino 2024-11-21 8.8 High
HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure.
CVE-2020-4104 1 Hcltech 1 Bigfix Webui 2024-11-21 5.4 Medium
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855&sys_kb_id=971d99ed1b8ed01c086dcbfc0a4bcb6a.
CVE-2020-4102 1 Hcltech 1 Notes 2024-11-21 6.7 Medium
HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Notes or execute attacker-controlled code on the client system.
CVE-2020-4101 1 Hcltech 1 Hcl Digital Experience 2024-11-21 9.8 Critical
"HCL Digital Experience is susceptible to Server Side Request Forgery."
CVE-2020-4099 1 Hcltech 1 Verse 2024-11-21 5.9 Medium
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.
CVE-2020-4097 1 Hcltech 1 Notes 2024-11-21 6.8 Medium
In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an attacker resulting in a buffer overflow. This could enable an attacker to crash HCL Notes or execute attacker-controlled code on the client.
CVE-2020-4095 1 Hcltech 1 Bigfix Platform 2024-11-21 6.0 Medium
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."
CVE-2020-4092 1 Hcltech 1 Hcl Nomad 2024-11-21 5.3 Medium
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can potentially expose sensitive information including but not limited to server names, user IDs and document content."
CVE-2020-4089 1 Hcltech 1 Notes 2024-11-21 6.5 Medium
HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and 11 are affected.
CVE-2020-4085 1 Hcltech 1 Connections 2024-11-21 6.5 Medium
"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."
CVE-2020-4084 1 Hcltech 1 Connections 2024-11-21 5.4 Medium
HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2020-4083 1 Hcltech 1 Connections 2024-11-21 5.5 Medium
HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.