Vulnerabilidades em HCL Software

384 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2023-50344MEDIUMUnauthenticated File Downloads affect DRYiCE MyXalyticsEPSS 0.3%CVE-2024-23584MEDIUMHCL BigFix Asset Discovery is affected by a security vulnerabilityEPSS 0.3%CVE-2024-42207MEDIUMHCL iAutomate is affected by a session fixation vulnerabilityEPSS 0.3%CVE-2024-30148MEDIUMHCL Leap is affected by improper access controlEPSS 0.3%CVE-2025-52619MEDIUMHCL BigFix SaaS Authentication Service is affected by a sensitive information disclosureEPSS 0.3%CVE-2024-42169HIGHHCL MyXalytics is affected by insecure direct object referencesEPSS 0.3%CVE-2026-35145LOWHCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability.EPSS 0.3%CVE-2026-67102HIGHHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.3%CVE-2024-23554MEDIUMHCL BigFix Platform is susceptible to Cross-Site Request Forgery EPSS 0.3%CVE-2024-42191MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to COM hijackingEPSS 0.3%CVE-2024-42190MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijackingEPSS 0.3%CVE-2024-42193LOWHCL BigFix Web Reports is susceptible to a Man-In-The-Middle (MITM) attackEPSS 0.3%CVE-2025-59870HIGHImproper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security riskEPSS 0.3%CVE-2024-30106LOWHCL Connections is vulnerable to an information disclosure vulnerabilityEPSS 0.3%CVE-2025-0256MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to a sensitive information disclosureEPSS 0.3%CVE-2026-67101CRITICALHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.3%CVE-2024-42208LOWHCL Connections is vulnerable to an information disclosure vulnerabilityEPSS 0.3%CVE-2022-42453MEDIUMHCL BigFix Platform is affected by insufficient warningsEPSS 0.3%CVE-2022-42449MEDIUMHCL Domino Volt is affected by an unrestricted upload of a dangerous file typeEPSS 0.3%CVE-2022-27562MEDIUMHCL Domino Volt is affected by an unrestricted upload of a dangerous file typeEPSS 0.3%