Vulnerabilidades en HCL Software

384 resultados
Análisis Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2025-62329MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to an insufficient session expiration vulnerabilityEPSS 0.2%CVE-2025-62342MEDIUMHCL IntelliOps Event Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2025-55278HIGHHCL DevOps Loop is susceptible to an improper authentication vulnerabilityEPSS 0.2%CVE-2025-52659LOWHCL AION is affected by a Cacheable HTTP Response vulnerabilityEPSS 0.2%CVE-2025-62343LOWHCL IntelliOps Event Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2021-27751MEDIUMHCL Commerce is affected by an Insufficient Session Expiration vulnerability.EPSS 0.2%CVE-2025-62307MEDIUMHCL IntelliOps Event Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2025-31994MEDIUMHCL Unica Campaign is vulnerable to Reflected Cross-Site Scripting (XSS)EPSS 0.2%CVE-2022-38661MEDIUMHCL Workload Automation is affected by a vulnerability in Jlog component of the Master Domain ManagerEPSS 0.2%CVE-2025-31954MEDIUMHCL iAutomate is susceptible to a sensitive information disclosureEPSS 0.2%CVE-2021-27785LOWHCL Commerce could allow a local attacker to obtain sensitive personal information (CVE-2021-27785)EPSS 0.2%CVE-2025-52622MEDIUMHCL BigFix SaaS Remediate is affected by a security vulnerabilityEPSS 0.2%CVE-2023-23342MEDIUMHCL Nomad for web is affected by cryptographic validation of local data access that can be circumventedEPSS 0.2%CVE-2024-42181LOWHCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerabilityEPSS 0.2%CVE-2025-52661LOWHCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resultiEPSS 0.2%CVE-2025-31974LOWHCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-OnlyEPSS 0.2%CVE-2025-52654MEDIUMHCL MyXalytics is affected by an HTML InjectionEPSS 0.2%CVE-2026-56570LOWHCL iControl is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2025-55252LOWHCL AION is affected by a Weak Password Policy vulnerabilityEPSS 0.2%CVE-2023-37512LOWHCL Traveler Companion is vulnerable to revealing sensitive information via the task switcherEPSS 0.2%