Filtered by vendor Hcltech Subscriptions
Total 178 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-28010 1 Hcltech 1 Domino 2024-08-02 4 Medium
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.
CVE-2023-28017 1 Hcltech 1 Connections 2024-08-02 5.4 Medium
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
CVE-2023-28014 1 Hcltech 1 Bigfix Mobile 2024-08-02 6.6 Medium
HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.
CVE-2023-28019 1 Hcltech 1 Bigfix Webui 2024-08-02 5.5 Medium
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.
CVE-2023-28022 1 Hcltech 1 Connections 2024-08-02 3.5 Low
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
CVE-2023-28021 1 Hcltech 1 Bigfix Webui 2024-08-02 5.9 Medium
The BigFix WebUI uses weak cipher suites.
CVE-2023-28013 1 Hcltech 1 Verse 2024-08-02 6.5 Medium
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
CVE-2023-28008 1 Hcltech 1 Workload Automation 2024-08-02 7.1 High
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
CVE-2023-28009 1 Hcltech 1 Workload Automation 2024-08-02 6.5 Medium
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
CVE-2023-23342 1 Hcltech 1 Hcl Nomad 2024-08-02 6.6 Medium
If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented. 
CVE-2023-23346 1 Hcltech 1 Dryice Mycloud 2024-08-02 6.4 Medium
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
CVE-2023-23343 1 Hcltech 1 Bigfix Osd Bare Metal Server 2024-08-02 2.4 Low
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain.
CVE-2023-23347 1 Hcltech 1 Dryice Iautomate 2024-08-02 6.4 Medium
HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
CVE-2023-23344 1 Hcltech 1 Bigfix Webui Insights 2024-08-02 3 Low
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
CVE-2024-30107 1 Hcltech 1 Connections 2024-08-02 3.5 Low
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.
CVE-2024-23562 1 Hcltech 1 Domino 2024-08-01 5.3 Medium
This vulnerability is being re-assessed.  Vulnerability details will be updated. The security bulletin will be republished when further details are available.
CVE-2024-23553 1 Hcltech 1 Bigfix Platform 2024-08-01 3 Low
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
CVE-2024-23588 1 Hcltech 1 Nomad Server On Domino 2024-08-01 5.3 Medium
HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.