Vulnerabilidades em HCL Software

384 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2022-27548MEDIUMHCL Launch is vulnerable to information disclosure which can be read by a local user.EPSS 0.5%CVE-2023-28022LOWHCL Connections is vulnerable to sensitive information disclosureEPSS 0.5%CVE-2025-31995LOWHCL Unica MaxAI Workbench is vulnerable to improper input validationEPSS 0.5%CVE-2023-45701MEDIUMHCL Launch is susceptible to sensitive information disclosureEPSS 0.5%CVE-2023-37502CRITICALAn unrestricted file upload vulnerability affects HCL CompassEPSS 0.5%CVE-2024-23562MEDIUMHCL Domino is susceptible to an information disclosure vulnerabilityEPSS 0.5%CVE-2023-37495MEDIUMHCL Domino is susceptible to a weak cryptography vulnerabilityEPSS 0.5%CVE-2023-45703MEDIUMHCL Launch is susceptible to a Denial of Service vulnerabilityEPSS 0.5%CVE-2024-30110LOWLack of input validation vulnerability affects DRYiCE AEX v10EPSS 0.5%CVE-2021-27773MEDIUMHCL Sametime is vulnerable to clickjackingEPSS 0.5%CVE-2022-27560MEDIUMAn insufficiently protected credential vulnerability affects HCL VersionVault ExpressEPSS 0.5%CVE-2026-56455MEDIUMHCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS).EPSS 0.5%CVE-2023-37503HIGHA weak password requirements vulnerability affects HCL CompassEPSS 0.5%CVE-2025-59872MEDIUMHCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,EPSS 0.5%CVE-2024-23576HIGHHCL Commerce is potentially affected by a denial of service and information disclosure vulnerabilityEPSS 0.5%CVE-2023-28015MEDIUMHCL Domino AppDev Pack is susceptible to a User Account Enumeration vulnerabilityEPSS 0.4%CVE-2022-27561HIGHHCL Traveler is susceptible to a Reflected Cross-Site Scripting vulnerability in the web admin (LotusTraveler.nsf)EPSS 0.4%CVE-2023-28019MEDIUMAn SQL injection affects BigFix WebUI APIEPSS 0.4%CVE-2023-45696MEDIUMHCL Sametime is impacted by an autocomplete enabled vulnerabilityEPSS 0.4%CVE-2022-27544MEDIUMHCL BigFix Web Reports authorized users may see sensitive information in clear textEPSS 0.4%