Vulnerabilidades em HCL Software

355 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2023-37536HIGHHCL BigFix Platform is vulnerable to an integer overflow in xerces-c++ 3.2.3EPSS 1.4%CVE-2023-45723HIGHPath Traversal which allows file upload capability affects DRYiCE MyXalyticsEPSS 1.0%CVE-2023-28012MEDIUMHCL BigFix Mobile can be affected by a command injection vulnerability EPSS 0.9%CVE-2023-28008HIGHHCL Workload Automation is vulnerable to XML External Entity (XXE) InjectionEPSS 0.8%CVE-2021-27777HIGHHCL Unica Platform is vulnerable to XML External Entity (XXE) injectionEPSS 0.8%CVE-2023-28009MEDIUMHCL Workload Automation is vulnerable to XML External Entity (XXE) InjectionEPSS 0.8%CVE-2021-27769MEDIUMHCL Sametime is vulnerable to an information disclosureEPSS 0.7%CVE-2021-27780MEDIUMHCL BigFix Mobile / Modern Client Management is vulnerable to unauthenticated XML interactionEPSS 0.7%CVE-2021-27770MEDIUMHCL Sametime is vulnerable to arbitrary HTTP requestsEPSS 0.7%CVE-2022-44755CRITICALHCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyViewEPSS 0.7%CVE-2021-27771HIGHHCL Sametime is susceptible a file transfer service vulnerabilityEPSS 0.7%CVE-2022-27563HIGHOverload/denial of service affects HCL VersionVault ExpressEPSS 0.7%CVE-2022-38656HIGHHCL Commerce, when using Elasticsearch, could be affected by a denial of service vulnerabilityEPSS 0.7%CVE-2021-27762MEDIUMHCL BigFix Platform is affected by misconfigured security-related HTTP headersEPSS 0.7%CVE-2021-27760MEDIUMHCL Notes 11.0 - 11.0.1 FP4 Sametime Embedded chat clients are vulnerable to group chats loading script on restartEPSS 0.7%CVE-2020-4082The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote atEPSS 0.7%CVE-2023-45722HIGHPath Traversal Arbitrary File Read affects DRYiCE MyXalyticsEPSS 0.7%CVE-2021-27772HIGHHCL Sametime is vulnerable to an information disclosureEPSS 0.6%CVE-2022-44753CRITICALHCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyViewEPSS 0.6%CVE-2022-44752CRITICALHCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyViewEPSS 0.6%