Vulnerabilidades en HCL Software

384 resultados
Análisis Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2024-30114LOWHCL Leap is affected by a cross-site scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-31996MEDIUMUnprotected files are impacting HCL Unica PlatformEPSS 0.2%CVE-2023-50349MEDIUMHCL Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2024-42173MEDIUMHCL MyXalytics is affected by an improper password policy implementation vulnerabilityEPSS 0.2%CVE-2024-42171MEDIUMHCL MyXalytics is affected by insufficient session expirationEPSS 0.2%CVE-2025-31988MEDIUMHCL Digital Experience is susceptible to cross site scripting (XSS)EPSS 0.2%CVE-2023-28014MEDIUMHCL BigFix Mobile can be affected by a cross-site scripting (XSS) vulnerability EPSS 0.2%CVE-2023-37534HIGHHCL Leap is affected by a Cross-site scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-31993LOWHCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF)EPSS 0.2%CVE-2024-30140MEDIUMHCL BigFix Compliance is affected by unvalidated redirects and forwardsEPSS 0.2%CVE-2024-30115MEDIUMHCL Domino Volt and Domino Leap are affected by a cross-site scripting (XSS) vulnerabilityEPSS 0.2%CVE-2020-4107HIGHHCL Domino is affected by an Insufficient Access Control vulnerabilityEPSS 0.2%CVE-2024-42212MEDIUMHCL BigFix Compliance is affected by an improper or missing SameSite attributeEPSS 0.2%CVE-2023-50355LOWHCL Sametime is impacted by generation of error messages containing sensitive informationEPSS 0.2%CVE-2024-42200MEDIUMHCL BigFix Web Reports is potentially susceptible to a Stored Cross-Site Scripting (XSS) attackEPSS 0.2%CVE-2022-44759MEDIUMHCL Leap is affected by Cross-site scripting (XSS)EPSS 0.2%CVE-2023-37535HIGHHCL Domino Volt and Domino Leap are affected by a Cross-site scripting (XSS) vulnerabilityEPSS 0.2%CVE-2024-42179LOWHCL MyXalytics is affected by sensitive information disclosure vulnerabilityEPSS 0.2%CVE-2024-42176LOWHCL MyXalytics is affected by concurrent login vulnerabilityEPSS 0.2%CVE-2024-30152MEDIUMHCL SX is affected by usage of a weak cryptographic algorithmEPSS 0.2%