Vulnerabilidades em HCL Software

384 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2026-9007MEDIUMReflected XSS in HCL NotesEPSS 0.4%CVE-2023-37526MEDIUMHCL DRYiCE Lucy v9 (now AEX) is affected by a Cross Origin Resource Sharing (CORS) VulnerabilityEPSS 0.4%CVE-2021-27781MEDIUMHCL BigFix Mobile / Modern Client Management is vulnerable to stored cross-site scriptingEPSS 0.4%CVE-2026-35147HIGHHCL DFXServer is affected by a Broken Authentication vulnerability via direct API access.EPSS 0.4%CVE-2023-23344LOWHCL BigFix WebUI Insights is susceptible to a lack of sufficient authorizationEPSS 0.4%CVE-2023-37533MEDIUMHCL Connections is vulnerable to reflected cross-site scriptingEPSS 0.4%CVE-2026-35149HIGHHCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.EPSS 0.4%CVE-2023-28017MEDIUMHCL Connections is vulnerable to cross-site scriptingEPSS 0.4%CVE-2023-37522MEDIUMHCL BigFix OSD Bare Metal Server WebUI is affected by missing or insecure tagsEPSS 0.4%CVE-2021-27774LOWAn injection vulnerability affects HCL Digital ExperienceEPSS 0.4%CVE-2023-37511LOWHCL Traveler To Do is affected by App Transport Security (ATS) settings allowing insecure loads in web contentEPSS 0.4%CVE-2026-56456MEDIUMHCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability.EPSS 0.4%CVE-2022-44756MEDIUMHCL BigFix Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validationEPSS 0.4%CVE-2023-37518MEDIUMA code injection vulnerability affects HCL BigFix ServiceNow Data FlowEPSS 0.4%CVE-2023-45715LOWHCL BigFix Platform is susceptible to a Denial of Service attackEPSS 0.4%CVE-2024-30128HIGHAn open proxy vulnerability affects HCL Nomad server on DominoEPSS 0.4%CVE-2024-42172MEDIUMHCL MyXalytics is affected by broken authenticationEPSS 0.4%CVE-2023-28010MEDIUMHCL Domino is susceptible to a sensitive information disclosure vulnerabilityEPSS 0.4%CVE-2023-37523MEDIUMHCL BigFix OSD Bare Metal Server WebUI is affected by missing or insecure tagsEPSS 0.4%CVE-2023-50343HIGHImproper Access Control (Controller APIs) affects DRYiCE MyXalyticsEPSS 0.4%