Vulnerabilidades em HCL Software

384 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2025-31998LOWHCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive informationEPSS 0.4%CVE-2022-42446MEDIUMHCL Sametime 12.0 and 12.0FP1 anonymous users have directory lookup accessEPSS 0.4%CVE-2024-30143MEDIUMA path traversal vulnerability in HCL AppScan Traffic RecorderEPSS 0.4%CVE-2023-37496HIGHHCL Verse is susceptible to a Stored Cross-Site Scripting (XSS) VulnerabilityEPSS 0.4%CVE-2022-38655MEDIUMHCL BigFix WebUI is affected by a missing-permission-check vulnerabilityEPSS 0.4%CVE-2023-37499HIGHA Persistent Cross-site Scripting (XSS) vulnerability affects HCL Unica PlatformEPSS 0.4%CVE-2023-37501HIGHA Persistent Cross-site Scripting (XSS) vulnerability affects HCL Unica CampaignEPSS 0.4%CVE-2023-37500HIGHA Persistent Cross-site Scripting (XSS) vulnerability affects HCL Unica PlatformEPSS 0.4%CVE-2025-0248HIGHHCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability,EPSS 0.4%CVE-2024-42168HIGHHCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerabilityEPSS 0.4%CVE-2023-45705LOWHCL BigFix Platform is susceptible to Server Side Request Forgery (SSRF)EPSS 0.4%CVE-2024-23556MEDIUMHCL BigFix Platform is impacted by a failure to restrict SSL/TLS renegotiationEPSS 0.4%CVE-2021-27778MEDIUMHCL Traveler is susceptible to a cross-site scripting vulnerability which could allow an attacker to execute a malicious script to access sensitive information.EPSS 0.4%CVE-2023-50341HIGHImproper Access Control affects DRYiCE MyXalyticsEPSS 0.4%CVE-2021-27761MEDIUMHCL BigFix Platform is affected by weak web transport securityEPSS 0.4%CVE-2023-28020MEDIUMURL redirection affects BigFix WebUIEPSS 0.4%CVE-2024-30109LOWLack of Clickjacking Protection vulnerability affects DRYiCE AEX v10EPSS 0.4%CVE-2021-27783MEDIUMHCL BigFix Mobile / Modern Client Management is vulnerable to sensitive information exposureEPSS 0.4%CVE-2024-23561MEDIUMHCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerabilityEPSS 0.4%CVE-2022-38662MEDIUMHCL Digital Experience is susceptible to open redirectsEPSS 0.4%