Filtered by vendor Hcltech Subscriptions
Total 178 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-42451 1 Hcltech 1 Bigfix Patch Management 2024-09-19 4.6 Medium
Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.
CVE-2022-44758 1 Hcltech 1 Bigfix Insights For Vulnerability Remediation 2024-09-18 6.5 Medium
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.
CVE-2022-44757 1 Hcltech 1 Bigfix Insights For Vulnerability Remediation 2024-09-18 6.5 Medium
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.
CVE-2023-37538 1 Hcltech 1 Digital Experience 2024-09-18 9.3 Critical
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
CVE-2023-37532 1 Hcltech 1 Commerce 2024-09-17 5.8 Medium
HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.
CVE-2021-27759 1 Hcltech 1 Bigfix Inventory 2024-09-17 2.3 Low
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.
CVE-2021-27760 1 Hcltech 1 Hcl Inotes 2024-09-17 4.6 Medium
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.
CVE-2021-27766 1 Hcltech 1 Bigfix Platform 2024-09-17 6.7 Medium
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
CVE-2022-27546 1 Hcltech 2 Domino, Hcl Inotes 2024-09-17 8.3 High
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.
CVE-2021-27772 1 Hcltech 1 Sametime 2024-09-17 7.1 High
Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it. This could lead to information leakage where confidential information discussed in private groups is read by other users without the users knowledge.
CVE-2022-27547 1 Hcltech 2 Domino, Hcl Inotes 2024-09-17 6.1 Medium
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
CVE-2021-27771 1 Hcltech 1 Sametime 2024-09-17 8.2 High
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.
CVE-2022-27558 1 Hcltech 2 Domino, Hcl Inotes 2024-09-17 5.9 Medium
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
CVE-2020-4099 1 Hcltech 1 Verse 2024-09-17 5.9 Medium
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.
CVE-2021-27779 1 Hcltech 1 Versionvault Express 2024-09-17 9.1 Critical
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
CVE-2021-27778 1 Hcltech 1 Traveler 2024-09-17 4.9 Medium
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.
CVE-2021-27773 1 Hcltech 1 Sametime 2024-09-16 4.2 Medium
This vulnerability allows users to execute a clickjacking attack in the meeting's chat.
CVE-2021-27783 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2024-09-16 6.8 Medium
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
CVE-2022-27544 1 Hcltech 1 Bigfix Platform 2024-09-16 5 Medium
BigFix Web Reports authorized users may see SMTP credentials in clear text.
CVE-2021-27780 1 Hcltech 2 Bigfix Mobile, Modern Client Management 2024-09-16 5.3 Medium
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.