Vulnerabilidades em HCL Software

384 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2025-0274MEDIUMHCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access controlEPSS 0.3%CVE-2025-0275MEDIUMHCL BigFix Mobile 3.3 and earlier is affected by improper access controlEPSS 0.3%CVE-2024-42174LOWHCL MyXalytics is affected by username enumeration vulnerabilityEPSS 0.3%CVE-2025-52616MEDIUMHCL Unica 12.1.10 is affected by an exposure of sensitive informationEPSS 0.3%CVE-2023-45706LOWHCL BigFix Platform is susceptible to Cross Site Scripting (XSS) and/or Man in the Middle (MITM) attackEPSS 0.3%CVE-2025-31953HIGHHCL iAutomate is affected by hardcoded credentialsEPSS 0.3%CVE-2024-30147MEDIUMHCL Leap is affected by a cross-site scripting (XSS) vulnerabilityEPSS 0.3%CVE-2024-42180LOWHCL MyXalytics is affected by a malicious file upload vulnerabilityEPSS 0.3%CVE-2024-42194LOWHCL BigFix Inventory is affected by an access control vulnerabilityEPSS 0.3%CVE-2024-30133MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerabilityEPSS 0.3%CVE-2024-30112MEDIUMHCL Connections is vulnerable to a cross-site scripting (XSS) vulnerabilityEPSS 0.3%CVE-2023-50345LOWOpen Redirect affects DRYiCE MyXalyticsEPSS 0.3%CVE-2024-23553LOWA cross-site scripting (XSS) vulnerability affects HCL BigFix PlatformEPSS 0.3%CVE-2026-56592MEDIUMHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.3%CVE-2023-37520HIGHHCL BigFix Platform is affected by Unathenticated Stored Cross-Site Scripting (XSS)EPSS 0.3%CVE-2025-0272MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to an HTML injection vulnerabilityEPSS 0.3%CVE-2023-45707MEDIUMHCL Connections Docs is vulnerable to Cross-Site Scripting (XSS)EPSS 0.3%CVE-2023-37519HIGHHCL BigFix Platform is affected by Unathenticated Stored Cross-Site Scripting (XSS)EPSS 0.2%CVE-2024-30145MEDIUMHCL Domino Volt and Domino Leap are affected by a cross-site scripting (XSS) vulnerabilityEPSS 0.2%CVE-2023-50351HIGHInsecure key rotation affects MyXalyticsEPSS 0.2%