Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Total 154 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-23344 1 Hcltech 1 Bigfix Webui Insights 2024-11-08 N/A 6.5 MEDIUM
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
CVE-2024-30106 1 Hcltech 1 Connections 2024-11-08 N/A 4.3 MEDIUM
HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entitled to due to the improper handling of request data.
CVE-2024-30122 1 Hcltech 1 Sametime 2024-11-06 N/A 5.3 MEDIUM
HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.
CVE-2023-50355 1 Hcltech 1 Sametime 2024-10-31 N/A 5.3 MEDIUM
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.
CVE-2023-23347 1 Hcltech 1 Dryice Iautomate 2024-10-29 N/A 7.1 HIGH
HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
CVE-2023-23346 1 Hcltech 1 Dryice Mycloud 2024-10-29 N/A 7.1 HIGH
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.
CVE-2022-42451 1 Hcltech 1 Bigfix Patch Management 2024-10-29 N/A 4.4 MEDIUM
Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.
CVE-2023-45698 1 Hcltech 1 Sametime Chat And Meetings 2024-10-28 N/A 6.1 MEDIUM
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
CVE-2024-23562 1 Hcltech 1 Domino 2024-10-23 N/A 7.5 HIGH
A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain information to launch further attacks against the affected system.
CVE-2024-30117 1 Hcltech 1 Bigfix Platform 2024-10-17 N/A 5.3 MEDIUM
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.
CVE-2023-28018 1 Hcltech 1 Connections 2024-10-16 N/A 6.5 MEDIUM
HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.
CVE-2024-30118 1 Hcltech 1 Connections 2024-10-10 N/A 5.7 MEDIUM
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly handling the request data.
CVE-2024-23586 1 Hcltech 2 Domino, Hcl Nomad 2024-10-07 N/A 7.5 HIGH
HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.
CVE-2023-28010 1 Hcltech 1 Domino 2024-09-26 N/A 5.3 MEDIUM
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.
CVE-2023-45696 1 Hcltech 1 Sametime 2024-09-05 N/A 7.5 HIGH
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.
CVE-2023-45718 1 Hcltech 1 Sametime 2024-09-05 N/A 7.5 HIGH
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  
CVE-2023-37539 1 Hcltech 1 Domino 2024-08-01 N/A 5.4 MEDIUM
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it.
CVE-2023-37536 3 Apache, Fedoraproject, Hcltech 3 Xerces-c\+\+, Fedora, Bigfix Platform 2024-08-01 N/A 8.8 HIGH
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
CVE-2024-23588 1 Hcltech 1 Nomad Server On Domino 2024-07-08 N/A 6.5 MEDIUM
HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.
CVE-2023-45716 1 Hcltech 1 Sametime 2024-02-26 N/A 4.1 MEDIUM
Sametime is impacted by sensitive information passed in URL.