VYPR

Vendor CVEs

HCL Software

All CVEs

622 total · sorted by risk
  • CVE-2020-4095MedJul 16, 2020
    risk 0.39cvss 6.0epss 0.00

    "BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment.…

  • CVE-2025-62300MedAug 20, 2026
    risk 0.38cvss 5.9epss 0.00

    HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior.

  • CVE-2025-55266MedMar 26, 2026
    risk 0.38cvss 5.9epss 0.00

    HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.

  • CVE-2025-52644MedMar 16, 2026
    risk 0.38cvss 5.8epss 0.00

    HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation…

  • CVE-2025-59873MedFeb 23, 2026
    risk 0.38cvss 5.9epss 0.00

    An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits sensitive session tokens and authentication identifiers within the URL query parameters . An attacker who gains access to any network log or operates a site…

  • CVE-2025-62330MedDec 16, 2025
    risk 0.38cvss 5.9epss 0.00

    HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related…

  • CVE-2024-30122MedOct 23, 2024
    risk 0.38cvss 5.8epss 0.00

    HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.

  • CVE-2024-23556MedMay 18, 2024
    risk 0.38cvss 5.9epss 0.00

    SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.

  • CVE-2023-37495MedFeb 29, 2024
    risk 0.38cvss 5.9epss 0.00

    Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the…

  • CVE-2023-50349MedFeb 9, 2024
    risk 0.38cvss 5.9epss 0.00

    Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the application.

  • CVE-2023-37532MedOct 23, 2023
    risk 0.38cvss 5.8epss 0.01

    HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.

  • CVE-2023-28021MedJul 18, 2023
    risk 0.38cvss 5.9epss 0.00

    The BigFix WebUI uses weak cipher suites.

  • CVE-2020-4099MedNov 1, 2022
    risk 0.38cvss 5.9epss 0.00

    The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.

  • CVE-2021-27784MedOct 31, 2022
    risk 0.38cvss 5.9epss 0.00

    The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.

  • CVE-2022-27558MedAug 29, 2022
    risk 0.38cvss 5.9epss 0.01

    HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.

  • CVE-2020-4126MedDec 1, 2020
    risk 0.38cvss 5.9epss 0.01

    HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1…

  • CVE-2017-1712MedJul 1, 2020
    risk 0.38cvss 5.9epss 0.01

    "A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a…

  • CVE-2025-55267MedMar 26, 2026
    risk 0.37cvss 5.7epss 0.00

    HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server.

  • CVE-2024-23554MedMay 18, 2024
    risk 0.37cvss 5.7epss 0.00

    Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).

  • CVE-2025-62314MedAug 13, 2026
    risk 0.36cvss 5.6epss 0.00

    HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under…

  • CVE-2025-55264MedMar 26, 2026
    risk 0.36cvss 5.5epss 0.00

    HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.

  • CVE-2025-52638MedMar 16, 2026
    risk 0.36cvss 5.6epss 0.00

    HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Running containers with root privileges may increase the potential security risk, as it grants elevated permissions within the container environment. Aligning…

  • CVE-2025-52627MedFeb 3, 2026
    risk 0.36cvss 5.5epss 0.00

    Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauthorized changes.This issue affects AION: 2.0.

  • CVE-2024-42197MedDec 11, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL Workload Scheduler stores user credentials in plain text which can be read by a local user.

  • CVE-2025-51733MedNov 28, 2025
    risk 0.36cvss 5.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

  • CVE-2024-42192MedOct 16, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.

  • CVE-2025-0273MedMar 27, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.

  • CVE-2024-30155MedMar 26, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

  • CVE-2024-42207MedFeb 5, 2025
    risk 0.36cvss 5.5epss 0.00

    HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.

  • CVE-2023-28018MedFeb 12, 2024
    risk 0.36cvss 5.5epss 0.00

    HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.

  • CVE-2023-37523MedJan 16, 2024
    risk 0.36cvss 5.6epss 0.00

    Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.

  • CVE-2023-37522MedJan 16, 2024
    risk 0.36cvss 5.6epss 0.00

    HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.

  • CVE-2023-28019MedJul 18, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.

  • CVE-2022-38654MedNov 4, 2022
    risk 0.36cvss 5.5epss 0.00

    HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a…

  • CVE-2021-27755MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.00

    "Sametime Android potential path traversal vulnerability when using File class"

  • CVE-2021-27753MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.00

    "Sametime Android PathTraversal Vulnerability"

  • CVE-2020-4083MedMar 5, 2020
    risk 0.36cvss 5.5epss 0.00

    HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.

  • CVE-2026-21754MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications.

  • CVE-2025-62307MedAug 20, 2026
    risk 0.35cvss 5.4epss 0.00

    HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.

  • CVE-2026-56619MedAug 10, 2026
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input.

  • CVE-2026-21766MedAug 5, 2026
    risk 0.35cvss 5.4epss 0.00

    The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs.  This only affects applications…

  • CVE-2025-62313MedMay 14, 2026
    risk 0.35cvss 5.4epss 0.00

    HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized access or account compromise under certain conditions.

  • CVE-2025-62310MedMay 14, 2026
    risk 0.35cvss 5.4epss 0.00

    HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive information to potential interception or unauthorized access under specific conditions.

  • CVE-2026-21788MedMar 19, 2026
    risk 0.35cvss 5.4epss 0.00

    HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code.  This may allow the attacker steal cookie-based…

  • CVE-2025-52622MedDec 2, 2025
    risk 0.35cvss 5.4epss 0.00

    The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the application's client-side security posture, making it more vulnerable to common web attacks that these headers are designed to mitigate, such as Cross-Site Scripting…

  • CVE-2025-31954MedNov 5, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were…

  • CVE-2025-52624MedOct 10, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects…

  • CVE-2025-31979MedAug 28, 2025
    risk 0.35cvss 5.4epss 0.00

    A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type restrictions during the upload process. An attacker may exploit this flaw to upload malicious or unauthorized files, such as scripts,…

  • CVE-2024-42212MedMay 5, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.

  • CVE-2024-42200MedApr 15, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.

Page 5 of 13