Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Total 193 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-42212 1 Hcltech 1 Bigfix Compliance 2025-06-17 N/A 5.4 MEDIUM
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.
CVE-2024-42213 1 Hcltech 1 Bigfix Compliance 2025-06-17 N/A 5.3 MEDIUM
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.
CVE-2024-30142 1 Hcltech 1 Bigfix Compliance 2025-06-17 N/A 3.8 LOW
HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.
CVE-2024-30141 1 Hcltech 1 Bigfix Compliance 2025-06-17 N/A 4.7 MEDIUM
HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about its environment, users, or associated data.
CVE-2024-30140 1 Hcltech 1 Bigfix Compliance 2025-06-17 N/A 5.4 MEDIUM
HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.
CVE-2024-30126 1 Hcltech 1 Bigfix Compliance 2025-06-17 N/A 4.7 MEDIUM
HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.
CVE-2024-30125 1 Hcltech 1 Bigfix Compliance 2025-06-17 N/A 6.2 MEDIUM
HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.
CVE-2023-50349 1 Hcltech 1 Sametime 2025-06-17 N/A 5.9 MEDIUM
Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the application.
CVE-2024-23553 1 Hcltech 1 Bigfix Platform 2025-06-03 N/A 3.0 LOW
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
CVE-2023-45718 1 Hcltech 1 Sametime 2025-06-03 N/A 3.9 LOW
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  
CVE-2023-45716 1 Hcltech 1 Sametime 2025-06-03 N/A 1.7 LOW
Sametime is impacted by sensitive information passed in URL.
CVE-2023-45696 1 Hcltech 1 Sametime 2025-06-03 N/A 4.0 MEDIUM
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.
CVE-2023-37531 1 Hcltech 1 Bigfix Platform 2025-06-03 N/A 3.3 LOW
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.
CVE-2023-37530 1 Hcltech 1 Bigfix Platform 2025-06-03 N/A 3.0 LOW
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information.
CVE-2023-37529 1 Hcltech 1 Bigfix Platform 2025-06-03 N/A 3.0 LOW
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerability as identified in CVE-2023-37530.
CVE-2023-37528 1 Hcltech 1 Bigfix Platform 2025-06-03 N/A 6.5 MEDIUM
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.
CVE-2023-37527 1 Hcltech 1 Bigfix Platform 2025-06-03 N/A 5.4 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.
CVE-2023-37518 1 Hcltech 1 Bigfix Servicenow Data Flow 2025-05-29 N/A 6.4 MEDIUM
HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.
CVE-2024-42179 1 Hcltech 1 Dryice Myxalytics 2025-05-16 N/A 2.0 LOW
HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version.
CVE-2024-42175 1 Hcltech 1 Dryice Myxalytics 2025-05-16 N/A 2.6 LOW
HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. This can lead to security vulnerabilities like SQL injection, XSS, and buffer overflow.