Vulnerabilidades em HCL Software

384 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2024-30134MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerabilityEPSS 0.2%CVE-2025-62340LOWHCL iControl was affected by Inadequate Session Timeout vulnerabilityEPSS 0.2%CVE-2021-27784MEDIUMHCL Launch container images may contain non-unique https certificates and database encryption keyEPSS 0.2%CVE-2025-55249LOWHCL AION is affected by a Missing Security Response Headers vulnerability.EPSS 0.2%CVE-2024-42209LOWHCL Connections is vulnerable to an information disclosure vulnerabilityEPSS 0.2%CVE-2024-30117LOWHCL BigFix Platform is affected by a DLL Hijack vulnerabilityEPSS 0.2%CVE-2024-30119LOWHCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security HeaderEPSS 0.2%CVE-2024-30146MEDIUMHCL Domino Leap is affected by improper access controlEPSS 0.2%CVE-2026-21848MEDIUMHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2025-31965HIGHHCL BigFix Remote Control is affected by an authorization bypass vulnerabilityEPSS 0.2%CVE-2024-42178LOWHCL MyXalytics is affected by a failure to restrict URL access vulnerabilityEPSS 0.2%CVE-2026-56568LOWHCL iControl is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2025-52658LOWHCL MyXalytics is affected by the use of vulnerable/outdated versionsEPSS 0.2%CVE-2025-52620MEDIUMHCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-52647MEDIUMHCL BigFix WebUI is affected by a host header poisoning vulnerabilityEPSS 0.2%CVE-2025-55254LOWHCL BigFix Remote Control is vulnerable to a Path-relative stylesheet import (PRSSI)EPSS 0.2%CVE-2021-27767MEDIUMHCL BigFix Platform Console is affected by a Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-59849MEDIUMHCL BigFix Remote Control is vulnerable to an insecure CSP configurationEPSS 0.2%CVE-2021-27766MEDIUMHCL BigFix Platform Client is affected by a Privilege Escalation VulnerabilityEPSS 0.2%CVE-2022-38654MEDIUMHCL Domino is susceptible to an information disclosure vulnerabilityEPSS 0.2%