Vulnerabilities in HCL Software

385 results
Vexday analysis

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2026-67103HIGHHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2025-31997MEDIUMHCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR)EPSS 0.2%CVE-2026-56454MEDIUMHCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1.EPSS 0.2%CVE-2024-30122MEDIUMHCL Sametime is impacted by misconfigured security related HTTP headersEPSS 0.2%CVE-2023-37517LOWHCL Domino Volt and Domino Leap are affected by missing "no cache" headersEPSS 0.2%CVE-2024-30126MEDIUMHCL BigFix Compliance is affected by a missing X-Frame-Options Header vulnerabilityEPSS 0.2%CVE-2022-42450MEDIUMHCL Domino Volt is affected by Cross-site scripting (XSS)EPSS 0.2%CVE-2025-31987MEDIUMHCL Connections Docs is vulnerable to a Denial of Service (DoS) attackEPSS 0.2%CVE-2026-21832MEDIUMHCL AION is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2024-23550MEDIUMHCL DevOps Deploy / HCL Launch (UCD) may be vulnerable to sensitive information disclosureEPSS 0.2%CVE-2025-0249LOWHCL IEM is affected by an improper invalidation of access or JWT token vulnerabilityEPSS 0.2%CVE-2025-52639LOWHCL Connections is vulnerable to sensitive information disclosureEPSS 0.2%CVE-2024-30155MEDIUMHCL SX is susceptible to cookie with Insecure, Improper, or Missing SameSite attribute vulnerabilityEPSS 0.2%CVE-2025-31979MEDIUMA File Upload Validation Bypass vulnerability has been identified in the HCL BigFix Service Management (SM)EPSS 0.2%CVE-2025-52615LOWHCL Unica Platform is impacted by misconfigured security related HTTP headersEPSS 0.2%CVE-2022-42454MEDIUMHCL BigFix Insights for Vulnerability Remediation (IVR) is vulnerable to improper certificate validationEPSS 0.2%CVE-2026-21822MEDIUMA path traversal vulnerability has been identified in HCL AppScan 360° (CVE-2026-21822).EPSS 0.2%CVE-2025-55251LOWHCL AION is affected by an Unrestricted File Upload vulnerabilityEPSS 0.2%CVE-2025-0251LOWHCL IEM is affected by a concurrent login vulnerabilityEPSS 0.2%CVE-2025-0253LOWHCL IEM is affected by a cookie attribute not set vulnerabilityEPSS 0.2%