Vendor CVEs
HCLTech
All CVEs
452 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-11518 | Hig | 0.53 | 8.1 | 0.01 | May 30, 2018 | A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio signals; based on the frequency, certain commands and functions are processed. Since these frequencies are accepted within a phone… | ||
| CVE-2023-37537 | Hig | 0.51 | 7.8 | 0.00 | Oct 17, 2023 | An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges. | ||
| CVE-2023-37520 | Hig | 0.50 | 7.7 | 0.00 | Dec 21, 2023 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay. | ||
| CVE-2023-37519 | Hig | 0.50 | 7.7 | 0.00 | Dec 21, 2023 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server. | ||
| CVE-2022-38658 | Hig | 0.50 | 7.7 | 0.00 | Dec 24, 2022 | BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data… | ||
| CVE-2024-42210 | Hig | 0.49 | 7.6 | 0.00 | Mar 19, 2026 | A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data… | ||
| CVE-2025-51735 | Hig | 0.49 | 7.5 | 0.00 | Nov 28, 2025 | CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0. | ||
| CVE-2025-52656 | Hig | 0.49 | 7.6 | 0.00 | Oct 3, 2025 | HCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application objects without proper validation or access controls, potentially allowing unauthorized modification of sensitive fields. | ||
| CVE-2025-52653 | Hig | 0.49 | 7.6 | 0.00 | Oct 3, 2025 | HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts, potentially resulting in unauthorized actions or access. | ||
| CVE-2025-31955 | Hig | 0.49 | 7.6 | 0.00 | Jul 24, 2025 | HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system. | ||
| CVE-2023-50341 | Hig | 0.49 | 7.6 | 0.00 | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" vulnerability, which could lead to inadvertent exposure of sensitive information and/or exposing a… | ||
| CVE-2023-45723 | Hig | 0.49 | 7.6 | 0.01 | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability. Certain endpoints permit users to manipulate the path (including the file name) where these files are stored on the server. | ||
| CVE-2022-27561 | Hig | 0.49 | 7.5 | 0.00 | Sep 15, 2022 | There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf). | ||
| CVE-2022-27563 | Hig | 0.49 | 7.5 | 0.01 | Aug 30, 2022 | An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service. | ||
| CVE-2021-27777 | Hig | 0.49 | 7.5 | 0.01 | May 12, 2022 | XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references. | ||
| CVE-2021-27756 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2022 | "TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it." | ||
| CVE-2021-27757 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2022 | " Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive… | ||
| CVE-2020-14255 | Hig | 0.49 | 7.5 | 0.01 | Feb 2, 2021 | HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditional on-premise installations. | ||
| CVE-2020-14273 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2020 | HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino server. | ||
| CVE-2020-14254 | Hig | 0.49 | 7.5 | 0.01 | Dec 16, 2020 | TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it. | ||
| CVE-2020-14258 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2020 | HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the client. Versions 9, 10 and 11 are affected. | ||
| CVE-2020-14234 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2020 | HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the ability to crash the server. Versions previous to release 9.0.1 FP10 IF6 and release 10.0.1 are affected. | ||
| CVE-2020-14230 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2020 | HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the server. Versions previous to releases 9.0.1… | ||
| CVE-2019-4326 | Hig | 0.49 | 7.5 | 0.01 | Oct 6, 2020 | "HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header." | ||
| CVE-2019-4327 | Hig | 0.49 | 7.5 | 0.01 | Apr 21, 2020 | "HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files." | ||
| CVE-2025-59870 | Hig | 0.48 | 7.4 | 0.00 | Jan 16, 2026 | HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk | ||
| CVE-2021-27764 | Hig | 0.48 | 7.4 | 0.01 | May 6, 2022 | Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI) | ||
| CVE-2025-55263 | Hig | 0.47 | 7.3 | 0.00 | Mar 26, 2026 | HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure repositories, they can easily retrieve these hardcoded secrets. | ||
| CVE-2025-52612 | Hig | 0.46 | 7.1 | 0.00 | Jun 4, 2026 | HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. . | ||
| CVE-2025-31953 | Hig | 0.46 | 7.1 | 0.00 | Jul 24, 2025 | HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties. | ||
| CVE-2025-31952 | Hig | 0.46 | 7.1 | 0.00 | Jul 24, 2025 | HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access. | ||
| CVE-2023-37535 | Hig | 0.46 | 7.1 | 0.00 | Apr 30, 2025 | Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters. | ||
| CVE-2023-37534 | Hig | 0.46 | 7.1 | 0.00 | Apr 24, 2025 | Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters. | ||
| CVE-2024-42169 | Hig | 0.46 | 7.1 | 0.00 | Jan 11, 2025 | HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user should be allowed to access specific data. | ||
| CVE-2023-50342 | Hig | 0.46 | 7.1 | 0.00 | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability. A user can obtain certain details about another user as a result of improper access control. | ||
| CVE-2023-37504 | Hig | 0.46 | 7.1 | 0.00 | Oct 19, 2023 | HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. If the session identifier can be discovered, it could be replayed to the application and used to impersonate the… | ||
| CVE-2023-28006 | Hig | 0.46 | 7.0 | 0.00 | Jun 22, 2023 | The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure. | ||
| CVE-2023-28008 | Hig | 0.46 | 7.1 | 0.01 | Apr 26, 2023 | HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | ||
| CVE-2021-27772 | Hig | 0.46 | 7.1 | 0.01 | May 12, 2022 | Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it.… | ||
| CVE-2019-16188 | Hig | 0.46 | 7.1 | 0.01 | Sep 25, 2019 | HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to open it. When the victim imports the .ozasmt file in… | ||
| CVE-2022-42453 | Med | 0.45 | 6.9 | 0.00 | Dec 19, 2022 | There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script. | ||
| CVE-2025-31991 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2026 | Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit. This vulnerability is fixed in 5.1.7. | ||
| CVE-2024-42170 | Med | 0.44 | 6.8 | 0.00 | Jan 11, 2025 | HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session. | ||
| CVE-2024-30134 | Med | 0.44 | 6.7 | 0.00 | Sep 26, 2024 | The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application. | ||
| CVE-2024-23583 | Med | 0.44 | 6.7 | 0.00 | May 17, 2024 | An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems. | ||
| CVE-2021-27783 | Med | 0.44 | 6.8 | 0.00 | May 25, 2022 | User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed. | ||
| CVE-2021-27770 | Med | 0.44 | 6.8 | 0.01 | May 12, 2022 | The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can specify an external URL where the online meeting will… | ||
| CVE-2021-27767 | Med | 0.44 | 6.7 | 0.00 | May 6, 2022 | The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying… | ||
| CVE-2021-27766 | Med | 0.44 | 6.7 | 0.00 | May 6, 2022 | The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying… | ||
| CVE-2021-27765 | Med | 0.44 | 6.7 | 0.00 | May 6, 2022 | The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying… |
- risk 0.53cvss 8.1epss 0.01
A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio signals; based on the frequency, certain commands and functions are processed. Since these frequencies are accepted within a phone…
- risk 0.51cvss 7.8epss 0.00
An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.
- risk 0.50cvss 7.7epss 0.00
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.
- risk 0.50cvss 7.7epss 0.00
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server.
- risk 0.50cvss 7.7epss 0.00
BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data…
- risk 0.49cvss 7.6epss 0.00
A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cross-site scripting (also known as second-order or persistent XSS) arises when an application receives data from an untrusted source and includes that data…
- risk 0.49cvss 7.5epss 0.00
CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
- risk 0.49cvss 7.6epss 0.00
HCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatically bound to application objects without proper validation or access controls, potentially allowing unauthorized modification of sensitive fields.
- risk 0.49cvss 7.6epss 0.00
HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts, potentially resulting in unauthorized actions or access.
- risk 0.49cvss 7.6epss 0.00
HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system.
- risk 0.49cvss 7.6epss 0.00
HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" vulnerability, which could lead to inadvertent exposure of sensitive information and/or exposing a…
- risk 0.49cvss 7.6epss 0.01
HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability. Certain endpoints permit users to manipulate the path (including the file name) where these files are stored on the server.
- risk 0.49cvss 7.5epss 0.00
There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).
- risk 0.49cvss 7.5epss 0.01
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
- risk 0.49cvss 7.5epss 0.01
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.
- risk 0.49cvss 7.5epss 0.01
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."
- risk 0.49cvss 7.5epss 0.01
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive…
- risk 0.49cvss 7.5epss 0.01
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditional on-premise installations.
- risk 0.49cvss 7.5epss 0.01
HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino server.
- risk 0.49cvss 7.5epss 0.01
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
- risk 0.49cvss 7.5epss 0.01
HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the client. Versions 9, 10 and 11 are affected.
- risk 0.49cvss 7.5epss 0.01
HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the ability to crash the server. Versions previous to release 9.0.1 FP10 IF6 and release 10.0.1 are affected.
- risk 0.49cvss 7.5epss 0.01
HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the server. Versions previous to releases 9.0.1…
- risk 0.49cvss 7.5epss 0.01
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
- risk 0.49cvss 7.5epss 0.01
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
- risk 0.48cvss 7.4epss 0.00
HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
- risk 0.48cvss 7.4epss 0.01
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)
- risk 0.47cvss 7.3epss 0.00
HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure repositories, they can easily retrieve these hardcoded secrets.
- risk 0.46cvss 7.1epss 0.00
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .
- risk 0.46cvss 7.1epss 0.00
HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.
- risk 0.46cvss 7.1epss 0.00
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.
- risk 0.46cvss 7.1epss 0.00
Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.
- risk 0.46cvss 7.1epss 0.00
Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.
- risk 0.46cvss 7.1epss 0.00
HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user should be allowed to access specific data.
- risk 0.46cvss 7.1epss 0.00
HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability. A user can obtain certain details about another user as a result of improper access control.
- risk 0.46cvss 7.1epss 0.00
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. If the session identifier can be discovered, it could be replayed to the application and used to impersonate the…
- risk 0.46cvss 7.0epss 0.00
The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.
- risk 0.46cvss 7.1epss 0.01
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
- risk 0.46cvss 7.1epss 0.01
Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it.…
- risk 0.46cvss 7.1epss 0.01
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to open it. When the victim imports the .ozasmt file in…
- risk 0.45cvss 6.9epss 0.00
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.
- risk 0.44cvss 6.8epss 0.00
Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit. This vulnerability is fixed in 5.1.7.
- risk 0.44cvss 6.8epss 0.00
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.
- risk 0.44cvss 6.7epss 0.00
The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application.
- risk 0.44cvss 6.7epss 0.00
An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.
- risk 0.44cvss 6.8epss 0.00
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
- risk 0.44cvss 6.8epss 0.01
The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can specify an external URL where the online meeting will…
- risk 0.44cvss 6.7epss 0.00
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying…
- risk 0.44cvss 6.7epss 0.00
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying…
- risk 0.44cvss 6.7epss 0.00
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying…
Page 2 of 10