Filtered by vendor Hcltech
Subscriptions
Total
178 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-28010 | 1 Hcltech | 1 Domino | 2024-08-02 | 4 Medium |
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks. | ||||
CVE-2023-28017 | 1 Hcltech | 1 Connections | 2024-08-02 | 5.4 Medium |
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise a user's account then launch other attacks. | ||||
CVE-2023-28014 | 1 Hcltech | 1 Bigfix Mobile | 2024-08-02 | 6.6 Medium |
HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application. | ||||
CVE-2023-28019 | 1 Hcltech | 1 Bigfix Webui | 2024-08-02 | 5.5 Medium |
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query. | ||||
CVE-2023-28022 | 1 Hcltech | 1 Connections | 2024-08-02 | 3.5 Low |
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data. | ||||
CVE-2023-28021 | 1 Hcltech | 1 Bigfix Webui | 2024-08-02 | 5.9 Medium |
The BigFix WebUI uses weak cipher suites. | ||||
CVE-2023-28013 | 1 Hcltech | 1 Verse | 2024-08-02 | 6.5 Medium |
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information. | ||||
CVE-2023-28008 | 1 Hcltech | 1 Workload Automation | 2024-08-02 | 7.1 High |
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | ||||
CVE-2023-28009 | 1 Hcltech | 1 Workload Automation | 2024-08-02 | 6.5 Medium |
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | ||||
CVE-2023-23342 | 1 Hcltech | 1 Hcl Nomad | 2024-08-02 | 6.6 Medium |
If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented. | ||||
CVE-2023-23346 | 1 Hcltech | 1 Dryice Mycloud | 2024-08-02 | 6.4 Medium |
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information. | ||||
CVE-2023-23343 | 1 Hcltech | 1 Bigfix Osd Bare Metal Server | 2024-08-02 | 2.4 Low |
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain. | ||||
CVE-2023-23347 | 1 Hcltech | 1 Dryice Iautomate | 2024-08-02 | 6.4 Medium |
HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information. | ||||
CVE-2023-23344 | 1 Hcltech | 1 Bigfix Webui Insights | 2024-08-02 | 3 Low |
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page. | ||||
CVE-2024-30107 | 1 Hcltech | 1 Connections | 2024-08-02 | 3.5 Low |
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios. | ||||
CVE-2024-23562 | 1 Hcltech | 1 Domino | 2024-08-01 | 5.3 Medium |
This vulnerability is being re-assessed. Vulnerability details will be updated. The security bulletin will be republished when further details are available. | ||||
CVE-2024-23553 | 1 Hcltech | 1 Bigfix Platform | 2024-08-01 | 3 Low |
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute. | ||||
CVE-2024-23588 | 1 Hcltech | 1 Nomad Server On Domino | 2024-08-01 | 5.3 Medium |
HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability. |