Vendor CVEs
HCL Software
All CVEs
622 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-4095 | Med | 0.39 | 6.0 | 0.00 | Jul 16, 2020 | "BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment.… | ||
| CVE-2025-62300 | Med | 0.38 | 5.9 | 0.00 | Aug 20, 2026 | HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior. | ||
| CVE-2025-55266 | Med | 0.38 | 5.9 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user. | ||
| CVE-2025-52644 | Med | 0.38 | 5.8 | 0.00 | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation… | ||
| CVE-2025-59873 | Med | 0.38 | 5.9 | 0.00 | Feb 23, 2026 | An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits sensitive session tokens and authentication identifiers within the URL query parameters . An attacker who gains access to any network log or operates a site… | ||
| CVE-2025-62330 | Med | 0.38 | 5.9 | 0.00 | Dec 16, 2025 | HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related… | ||
| CVE-2024-30122 | Med | 0.38 | 5.8 | 0.00 | Oct 23, 2024 | HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers. | ||
| CVE-2024-23556 | Med | 0.38 | 5.9 | 0.00 | May 18, 2024 | SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability. | ||
| CVE-2023-37495 | Med | 0.38 | 5.9 | 0.00 | Feb 29, 2024 | Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the… | ||
| CVE-2023-50349 | Med | 0.38 | 5.9 | 0.00 | Feb 9, 2024 | Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the application. | ||
| CVE-2023-37532 | Med | 0.38 | 5.8 | 0.01 | Oct 23, 2023 | HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system. | ||
| CVE-2023-28021 | Med | 0.38 | 5.9 | 0.00 | Jul 18, 2023 | The BigFix WebUI uses weak cipher suites. | ||
| CVE-2020-4099 | Med | 0.38 | 5.9 | 0.00 | Nov 1, 2022 | The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app. | ||
| CVE-2021-27784 | Med | 0.38 | 5.9 | 0.00 | Oct 31, 2022 | The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages. | ||
| CVE-2022-27558 | Med | 0.38 | 5.9 | 0.01 | Aug 29, 2022 | HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking. | ||
| CVE-2020-4126 | Med | 0.38 | 5.9 | 0.01 | Dec 1, 2020 | HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1… | ||
| CVE-2017-1712 | Med | 0.38 | 5.9 | 0.01 | Jul 1, 2020 | "A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a… | ||
| CVE-2025-55267 | Med | 0.37 | 5.7 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server. | ||
| CVE-2024-23554 | Med | 0.37 | 5.7 | 0.00 | May 18, 2024 | Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE). | ||
| CVE-2025-62314 | Med | 0.36 | 5.6 | 0.00 | Aug 13, 2026 | HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under… | ||
| CVE-2025-55264 | Med | 0.36 | 5.5 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover. | ||
| CVE-2025-52638 | Med | 0.36 | 5.6 | 0.00 | Mar 16, 2026 | HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Running containers with root privileges may increase the potential security risk, as it grants elevated permissions within the container environment. Aligning… | ||
| CVE-2025-52627 | Med | 0.36 | 5.5 | 0.00 | Feb 3, 2026 | Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauthorized changes.This issue affects AION: 2.0. | ||
| CVE-2024-42197 | Med | 0.36 | 5.5 | 0.00 | Dec 11, 2025 | HCL Workload Scheduler stores user credentials in plain text which can be read by a local user. | ||
| CVE-2025-51733 | Med | 0.36 | 5.5 | 0.00 | Nov 28, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0. | ||
| CVE-2024-42192 | Med | 0.36 | 5.5 | 0.00 | Oct 16, 2025 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications. | ||
| CVE-2025-0273 | Med | 0.36 | 5.5 | 0.00 | Mar 27, 2025 | HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user. | ||
| CVE-2024-30155 | Med | 0.36 | 5.5 | 0.00 | Mar 26, 2025 | HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF). | ||
| CVE-2024-42207 | Med | 0.36 | 5.5 | 0.00 | Feb 5, 2025 | HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim's session ID from their authenticated session. | ||
| CVE-2023-28018 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2024 | HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users. | ||
| CVE-2023-37523 | Med | 0.36 | 5.6 | 0.00 | Jan 16, 2024 | Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser. | ||
| CVE-2023-37522 | Med | 0.36 | 5.6 | 0.00 | Jan 16, 2024 | HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser. | ||
| CVE-2023-28019 | Med | 0.36 | 5.5 | 0.00 | Jul 18, 2023 | Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query. | ||
| CVE-2022-38654 | Med | 0.36 | 5.5 | 0.00 | Nov 4, 2022 | HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a… | ||
| CVE-2021-27755 | Med | 0.36 | 5.5 | 0.00 | Feb 21, 2022 | "Sametime Android potential path traversal vulnerability when using File class" | ||
| CVE-2021-27753 | Med | 0.36 | 5.5 | 0.00 | Feb 21, 2022 | "Sametime Android PathTraversal Vulnerability" | ||
| CVE-2020-4083 | Med | 0.36 | 5.5 | 0.00 | Mar 5, 2020 | HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user. | ||
| CVE-2026-21754 | Med | 0.35 | 5.4 | 0.00 | Aug 25, 2026 | HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications. | ||
| CVE-2025-62307 | Med | 0.35 | 5.4 | 0.00 | Aug 20, 2026 | HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing. | ||
| CVE-2026-56619 | Med | 0.35 | 5.4 | 0.00 | Aug 10, 2026 | HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input. | ||
| CVE-2026-21766 | Med | 0.35 | 5.4 | 0.00 | Aug 5, 2026 | The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications… | ||
| CVE-2025-62313 | Med | 0.35 | 5.4 | 0.00 | May 14, 2026 | HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized access or account compromise under certain conditions. | ||
| CVE-2025-62310 | Med | 0.35 | 5.4 | 0.00 | May 14, 2026 | HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive information to potential interception or unauthorized access under specific conditions. | ||
| CVE-2026-21788 | Med | 0.35 | 5.4 | 0.00 | Mar 19, 2026 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may allow the attacker steal cookie-based… | ||
| CVE-2025-52622 | Med | 0.35 | 5.4 | 0.00 | Dec 2, 2025 | The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the application's client-side security posture, making it more vulnerable to common web attacks that these headers are designed to mitigate, such as Cross-Site Scripting… | ||
| CVE-2025-31954 | Med | 0.35 | 5.4 | 0.00 | Nov 5, 2025 | HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were… | ||
| CVE-2025-52624 | Med | 0.35 | 5.4 | 0.00 | Oct 10, 2025 | A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects… | ||
| CVE-2025-31979 | Med | 0.35 | 5.4 | 0.00 | Aug 28, 2025 | A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type restrictions during the upload process. An attacker may exploit this flaw to upload malicious or unauthorized files, such as scripts,… | ||
| CVE-2024-42212 | Med | 0.35 | 5.4 | 0.00 | May 5, 2025 | HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions. | ||
| CVE-2024-42200 | Med | 0.35 | 5.4 | 0.00 | Apr 15, 2025 | HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input. |
- risk 0.39cvss 6.0epss 0.00
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment.…
- risk 0.38cvss 5.9epss 0.00
HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior.
- risk 0.38cvss 5.9epss 0.00
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.
- risk 0.38cvss 5.8epss 0.00
HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation…
- risk 0.38cvss 5.9epss 0.00
An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits sensitive session tokens and authentication identifiers within the URL query parameters . An attacker who gains access to any network log or operates a site…
- risk 0.38cvss 5.9epss 0.00
HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related…
- risk 0.38cvss 5.8epss 0.00
HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.
- risk 0.38cvss 5.9epss 0.00
SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.
- risk 0.38cvss 5.9epss 0.00
Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the…
- risk 0.38cvss 5.9epss 0.00
Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the application.
- risk 0.38cvss 5.8epss 0.01
HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.
- risk 0.38cvss 5.9epss 0.00
The BigFix WebUI uses weak cipher suites.
- risk 0.38cvss 5.9epss 0.00
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.
- risk 0.38cvss 5.9epss 0.00
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.
- risk 0.38cvss 5.9epss 0.01
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
- risk 0.38cvss 5.9epss 0.01
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1…
- risk 0.38cvss 5.9epss 0.01
"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a…
- risk 0.37cvss 5.7epss 0.00
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server.
- risk 0.37cvss 5.7epss 0.00
Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).
- risk 0.36cvss 5.6epss 0.00
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under…
- risk 0.36cvss 5.5epss 0.00
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.
- risk 0.36cvss 5.6epss 0.00
HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Running containers with root privileges may increase the potential security risk, as it grants elevated permissions within the container environment. Aligning…
- risk 0.36cvss 5.5epss 0.00
Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauthorized changes.This issue affects AION: 2.0.
- risk 0.36cvss 5.5epss 0.00
HCL Workload Scheduler stores user credentials in plain text which can be read by a local user.
- risk 0.36cvss 5.5epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
- risk 0.36cvss 5.5epss 0.00
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.
- risk 0.36cvss 5.5epss 0.00
HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.
- risk 0.36cvss 5.5epss 0.00
HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).
- risk 0.36cvss 5.5epss 0.00
HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim's session ID from their authenticated session.
- risk 0.36cvss 5.5epss 0.00
HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.
- risk 0.36cvss 5.6epss 0.00
Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.
- risk 0.36cvss 5.6epss 0.00
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.
- risk 0.36cvss 5.5epss 0.00
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.
- risk 0.36cvss 5.5epss 0.00
HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a…
- risk 0.36cvss 5.5epss 0.00
"Sametime Android potential path traversal vulnerability when using File class"
- risk 0.36cvss 5.5epss 0.00
"Sametime Android PathTraversal Vulnerability"
- risk 0.36cvss 5.5epss 0.00
HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.
- risk 0.35cvss 5.4epss 0.00
HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications.
- risk 0.35cvss 5.4epss 0.00
HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.
- risk 0.35cvss 5.4epss 0.00
HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input.
- risk 0.35cvss 5.4epss 0.00
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications…
- risk 0.35cvss 5.4epss 0.00
HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized access or account compromise under certain conditions.
- risk 0.35cvss 5.4epss 0.00
HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive information to potential interception or unauthorized access under specific conditions.
- risk 0.35cvss 5.4epss 0.00
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may allow the attacker steal cookie-based…
- risk 0.35cvss 5.4epss 0.00
The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the application's client-side security posture, making it more vulnerable to common web attacks that these headers are designed to mitigate, such as Cross-Site Scripting…
- risk 0.35cvss 5.4epss 0.00
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were…
- risk 0.35cvss 5.4epss 0.00
A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects…
- risk 0.35cvss 5.4epss 0.00
A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type restrictions during the upload process. An attacker may exploit this flaw to upload malicious or unauthorized files, such as scripts,…
- risk 0.35cvss 5.4epss 0.00
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.
- risk 0.35cvss 5.4epss 0.00
HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.
Page 5 of 13