Vulnerabilidades en HCL Software

384 resultados
Análisis Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2023-37540LOWHCL Sametime Chat is affected by an unimplemented feature in the UI EPSS 0.2%CVE-2023-37513LOWHCL Traveler To Do is vulnerable to revealing sensitive information via the task switcherEPSS 0.2%CVE-2024-42188LOWHCL Connections is vulnerable to a broken access control vulnerabilityEPSS 0.2%CVE-2025-0250LOWHCL IEM is affected by an authorization token sent in cookie vulnerabilityEPSS 0.2%CVE-2025-31992MEDIUMHCL MaxAI Assistant is susceptible to a HTML injection vulnerabilityEPSS 0.2%CVE-2026-56571LOWHCL iControl is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2026-21758LOWHCL Hive is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2024-23551MEDIUMHCL BigFix Compliance is potentially affected by Oracle database credentials stored at endpointEPSS 0.2%CVE-2026-56590MEDIUMHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2024-30149MEDIUMHCL AppScan Source is affected by an expired TLS/SSL certificateEPSS 0.2%CVE-2023-37537HIGHHCL AppScan Presence deployed as Windows service might be vulnerable to an Unquoted Service Path vulnerabilityEPSS 0.2%CVE-2024-30124MEDIUMHCL Sametime is impacted by insecure servicesEPSS 0.2%CVE-2025-62306MEDIUMHCL IntelliOps Event Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2024-42177LOWHCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilitiesEPSS 0.2%CVE-2024-23589MEDIUMHCL Glovius Cloud is susceptible to an Outdated Hash Algorithm vulnerabilityEPSS 0.2%CVE-2023-28023MEDIUMHCL BigFix WebUI Software Distribution is affected by a cross site server request forgery vulnerabilityEPSS 0.2%CVE-2025-31969MEDIUMHCL Unica Platform is impacted by misconfigured Content Security Policy (CSP)EPSS 0.2%CVE-2025-52657LOWHCL MyXalytics is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2026-56608LOWHCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609).EPSS 0.2%CVE-2023-45702MEDIUMHCL Launch Agent as a Windows service is vulnerable to a Denial of ServiceEPSS 0.2%