Filtered by vendor Hcltech
Subscribe
Total
175 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-27770 | 1 Hcltech | 1 Sametime | 2023-06-30 | 6.8 MEDIUM | 8.8 HIGH |
The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can specify an external URL where the online meeting will take place. | |||||
CVE-2021-27764 | 1 Hcltech | 1 Bigfix Webui | 2023-06-30 | 4.3 MEDIUM | 6.5 MEDIUM |
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI) | |||||
CVE-2023-28008 | 1 Hcltech | 1 Workload Automation | 2023-05-05 | N/A | 8.1 HIGH |
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |||||
CVE-2023-28009 | 1 Hcltech | 1 Workload Automation | 2023-05-05 | N/A | 8.1 HIGH |
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |||||
CVE-2020-4099 | 1 Hcltech | 1 Verse | 2022-11-03 | N/A | 7.5 HIGH |
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app. | |||||
CVE-2021-27784 | 1 Hcltech | 1 Hcl Launch Container Image | 2022-11-02 | N/A | 7.5 HIGH |
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages. | |||||
CVE-2021-27774 | 1 Hcltech | 1 Hcl Digital Experience | 2022-09-24 | N/A | 5.4 MEDIUM |
User input included in error response, which could be used in a phishing attack. | |||||
CVE-2020-4107 | 1 Hcltech | 1 Domino | 2022-09-20 | 4.6 MEDIUM | 7.8 HIGH |
HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure. | |||||
CVE-2022-27561 | 1 Hcltech | 1 Traveler | 2022-09-19 | N/A | 4.8 MEDIUM |
There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf). | |||||
CVE-2022-27560 | 1 Hcltech | 1 Versionvault Express | 2022-09-08 | N/A | 6.5 MEDIUM |
HCL VersionVault Express exposes administrator credentials. | |||||
CVE-2022-27563 | 1 Hcltech | 1 Versionvault Express | 2022-09-06 | N/A | 7.5 HIGH |
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service. | |||||
CVE-2022-27558 | 1 Hcltech | 2 Domino, Hcl Inotes | 2022-09-01 | N/A | 7.5 HIGH |
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking. | |||||
CVE-2022-27547 | 1 Hcltech | 2 Domino, Hcl Inotes | 2022-09-01 | N/A | 7.4 HIGH |
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc. | |||||
CVE-2022-27546 | 1 Hcltech | 2 Domino, Hcl Inotes | 2022-09-01 | N/A | 6.1 MEDIUM |
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials. | |||||
CVE-2021-27777 | 1 Hcltech | 1 Unica | 2022-08-06 | 5.0 MEDIUM | 7.5 HIGH |
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references. | |||||
CVE-2021-27760 | 1 Hcltech | 1 Hcl Inotes | 2022-07-29 | 6.0 MEDIUM | 5.5 MEDIUM |
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code. | |||||
CVE-2021-27769 | 1 Hcltech | 1 Sametime | 2022-07-29 | 5.0 MEDIUM | 5.3 MEDIUM |
Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any information that could be used for an attack should be limited whenever possible. | |||||
CVE-2021-27772 | 1 Hcltech | 1 Sametime | 2022-07-29 | 4.0 MEDIUM | 6.5 MEDIUM |
Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it. This could lead to information leakage where confidential information discussed in private groups is read by other users without the users knowledge. | |||||
CVE-2022-27544 | 1 Hcltech | 1 Bigfix Platform | 2022-07-27 | N/A | 6.5 MEDIUM |
BigFix Web Reports authorized users may see SMTP credentials in clear text. | |||||
CVE-2022-27545 | 1 Hcltech | 1 Bigfix Platform | 2022-07-27 | N/A | 5.4 MEDIUM |
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page. |