Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Total 172 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-27558 1 Hcltech 2 Domino, Hcl Inotes 2023-12-10 N/A 7.5 HIGH
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
CVE-2022-27547 1 Hcltech 2 Domino, Hcl Inotes 2023-12-10 N/A 7.4 HIGH
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
CVE-2022-27545 1 Hcltech 1 Bigfix Platform 2023-12-10 N/A 5.4 MEDIUM
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
CVE-2022-27560 1 Hcltech 1 Versionvault Express 2023-12-10 N/A 6.5 MEDIUM
HCL VersionVault Express exposes administrator credentials.
CVE-2021-27774 1 Hcltech 1 Hcl Digital Experience 2023-12-10 N/A 5.4 MEDIUM
User input included in error response, which could be used in a phishing attack.
CVE-2022-38654 1 Hcltech 1 Domino 2023-12-10 N/A 5.5 MEDIUM
HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a user's person record.
CVE-2022-27561 1 Hcltech 1 Traveler 2023-12-10 N/A 4.8 MEDIUM
There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).
CVE-2022-27546 1 Hcltech 2 Domino, Hcl Inotes 2023-12-10 N/A 6.1 MEDIUM
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.
CVE-2020-4099 1 Hcltech 1 Verse 2023-12-10 N/A 7.5 HIGH
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.
CVE-2021-27784 1 Hcltech 1 Hcl Launch Container Image 2023-12-10 N/A 7.5 HIGH
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.
CVE-2021-27773 1 Hcltech 1 Sametime 2023-12-10 4.3 MEDIUM 4.3 MEDIUM
This vulnerability allows users to execute a clickjacking attack in the meeting's chat.
CVE-2021-27771 1 Hcltech 1 Sametime 2023-12-10 6.5 MEDIUM 7.6 HIGH
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.
CVE-2021-27766 1 Hcltech 1 Bigfix Platform 2023-12-10 4.6 MEDIUM 7.8 HIGH
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
CVE-2021-27772 1 Hcltech 1 Sametime 2023-12-10 4.0 MEDIUM 6.5 MEDIUM
Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it. This could lead to information leakage where confidential information discussed in private groups is read by other users without the users knowledge.
CVE-2021-27783 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2023-12-10 4.0 MEDIUM 6.5 MEDIUM
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
CVE-2021-27786 1 Hcltech 1 Onetest Server 2023-12-10 6.8 MEDIUM 9.8 CRITICAL
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.
CVE-2021-27781 1 Hcltech 2 Bigfix Mobile, Modern Client Management 2023-12-10 3.5 LOW 4.8 MEDIUM
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
CVE-2021-27765 1 Hcltech 1 Bigfix Platform 2023-12-10 4.6 MEDIUM 7.8 HIGH
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
CVE-2021-27769 1 Hcltech 1 Sametime 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any information that could be used for an attack should be limited whenever possible.
CVE-2021-27757 1 Hcltech 1 Bigfix Insights 2023-12-10 5.0 MEDIUM 7.5 HIGH
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive information."