Vulnerabilidades em HCL Software

384 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2025-31976MEDIUMHCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentialsEPSS 0.2%CVE-2026-35143LOWHCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.EPSS 0.2%CVE-2025-62299MEDIUMHCL IntelliOps Event Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2026-56597LOWHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2024-30127LOWHCL Leap is affected by missing "no cache" headersEPSS 0.2%CVE-2023-37516LOWHCL Leap is affected by missing "no cache" headersEPSS 0.2%CVE-2024-42192MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakageEPSS 0.2%CVE-2025-55250LOWHCL AION is affected by a Technical Error Disclosure vulnerabilityEPSS 0.2%CVE-2024-23583MEDIUMHCL BigFix Platform is susceptible to insufficiently protected credentialsEPSS 0.2%CVE-2024-42187MEDIUMHCL BigFix Patch Download Plug-ins are affected by path traversal vulnerabilityEPSS 0.2%CVE-2024-23563LOWHCL Connections Docs is vulnerable to a sensitive information disclosureEPSS 0.2%CVE-2025-52602MEDIUMHCL BigFix Query is affected by a sensitive information disclosure vulnerability in the WebUI Query applicationEPSS 0.2%CVE-2025-0273MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to Insertion of Sensitive Information into Log File vulnerabilityEPSS 0.2%CVE-2023-23348MEDIUMHCL Launch is vulnerable to sensitive information disclosureEPSS 0.2%CVE-2025-62330MEDIUMHCL DevOps Deploy is susceptible to a cleartext transmission of sensitive informationEPSS 0.2%CVE-2023-50350HIGHA broken cryptographic algorithm impacts MyXalyticsEPSS 0.2%CVE-2025-31961LOWHCL Connections is vulnerable to broken access controlEPSS 0.2%CVE-2025-52621MEDIUMHCL BigFix SaaS Authentication Service is vulnerable to cache poisoningEPSS 0.2%CVE-2024-42196MEDIUMHCL Launch is susceptible to Insertion of Sensitive Information into Log File vulnerabilityEPSS 0.2%CVE-2025-31982LOWHCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directlEPSS 0.2%