Vulnerabilities in HCL

89 results
Vexday analysis

O portfólio de vulnerabilidades da HCL reúne 88 CVEs catalogadas, com volume recente relevante — 32 entradas nos últimos 90 dias —, sinalizando atividade contínua de descoberta e divulgação. Apesar disso, o risco operacional imediato é baixo: nenhuma CVE consta no catálogo KEV da CISA, taxa inferior à média geral do catálogo, e nenhuma prova de conceito pública foi identificada. A falha mais frequente é CWE-200 (exposição indevida de informações), padrão que costuma favorecer reconhecimento e coleta de dados sensíveis quando combinado a outras fraquezas. A CVE mais perigosa atualmente monitorada, CVE-2020-14258, apresenta EPSS de 0,0125, indicando probabilidade de exploração ativa baixa, mas sua antiguidade reforça a importância de verificar se os ativos afetados receberam as correções devidas.

CVE-2025-52612HIGHHCL iControl was affected by Export CSV - CSV Injection vulnerability.EPSS 0.2%CVE-2025-52628MEDIUMHCL AION is susceptible to Missing SameSite vulnerabilityEPSS 0.2%CVE-2025-31966LOWBoolean-Based SQL Injection in Multiple Unica ComponentsEPSS 0.2%CVE-2025-55263HIGHHCL Aftermarket DPC is affected by Hardcoded Sensitive DataEPSS 0.2%CVE-2025-52655LOWHCL MyXalytics is affected by a Cross-Domain Script Include vulnerability.EPSS 0.2%CVE-2025-52633LOWHCL AION is susceptible to Missing Content-Security-PolicyEPSS 0.2%CVE-2025-62347MEDIUMHCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security EPSS 0.2%CVE-2025-55274LOWHCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerabilityEPSS 0.2%CVE-2025-31973MEDIUMHCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'EPSS 0.2%CVE-2025-62313MEDIUMHCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced.EPSS 0.2%CVE-2025-55277LOWHCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerabilityEPSS 0.2%CVE-2025-31975LOWHCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified.EPSS 0.2%CVE-2025-52606MEDIUMHCL iControl was affected by Weak Input Validation vulnerability. .EPSS 0.2%CVE-2025-59853LOWHCL DFXAnalytics is affected by an Improper Error Handling vulnerabilityEPSS 0.2%CVE-2025-52609LOWHCL iControl was affected by Missing Security Headers vulnerability.EPSS 0.2%CVE-2025-62320MEDIUMHTML Injection Leading to Data Exfiltration to External Server vulnerability affects HCL Unica PlatformEPSS 0.2%CVE-2025-52623LOWHCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerabilityEPSS 0.2%CVE-2025-52611LOWHCL iControl was affected by Unhandled Exception - Stack Trace Disclosure vulnerabilityEPSS 0.2%CVE-2025-31985LOWHCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” headerEPSS 0.2%CVE-2025-52627MEDIUMHCL AION is susceptible to Incorrect Permission Assignment for Critical ResourceEPSS 0.2%