VYPR
Vendor

Hcltechsw

Products
11
CVEs
44
Across products
56
Status
Private

Products

11

Recent CVEs

44
View all 44 CVEs →
  • CVE-2020-14245CriFeb 4, 2021
    risk 0.64cvss 9.8epss 0.01

    HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources.

  • CVE-2020-14275CriJan 12, 2021
    risk 0.64cvss 9.8epss 0.01

    Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

  • CVE-2021-27741CriAug 13, 2021
    risk 0.59cvss 9.1epss 0.01

    " Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"

  • CVE-2020-14231HigDec 22, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would…

  • CVE-2022-38656HigDec 12, 2022
    risk 0.56cvss 8.6epss 0.01

    HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.

  • CVE-2020-14274HigJan 12, 2021
    risk 0.49cvss 7.5epss 0.01

    Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.

  • CVE-2025-0255HigMar 24, 2025
    risk 0.47cvss 7.2epss 0.01

    HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.

  • CVE-2024-23576HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.00

    Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

  • CVE-2022-44756MedDec 21, 2022
    risk 0.42cvss 6.4epss 0.00

    Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires privileged access. 

  • CVE-2022-42454MedDec 21, 2022
    risk 0.42cvss 6.4epss 0.00

    Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure.  This requires privileged network access.

  • CVE-2020-14247MedFeb 4, 2021
    risk 0.42cvss 6.5epss 0.01

    HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.

  • CVE-2020-14225MedDec 21, 2020
    risk 0.42cvss 6.5epss 0.01

    HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing…

  • CVE-2024-23558MedApr 15, 2024
    risk 0.41cvss 6.3epss 0.00

    HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2024-42196MedDec 6, 2024
    risk 0.40cvss 6.2epss 0.00

    HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.

  • CVE-2024-23559MedApr 15, 2024
    risk 0.40cvss 6.1epss 0.00

    HCL DevOps Deploy / Launch is generating an obsolete HTTP header.

  • CVE-2024-23550MedFeb 3, 2024
    risk 0.40cvss 6.2epss 0.00

    HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.

  • CVE-2023-45702MedDec 28, 2023
    risk 0.40cvss 6.2epss 0.00

    An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts..

  • CVE-2022-38661MedDec 12, 2022
    risk 0.40cvss 6.2epss 0.00

    HCL Workload Automation could allow a local user to overwrite key system files which would cause the system to crash.

  • CVE-2025-62330MedDec 16, 2025
    risk 0.38cvss 5.9epss 0.00

    HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related…

  • CVE-2023-37523MedJan 16, 2024
    risk 0.36cvss 5.6epss 0.00

    Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.