Vulnerabilidades em HCL Software

384 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2023-37538CRITICALHCL Digital Experience is susceptible to cross site scripting (XSS)EPSS 0.4%CVE-2023-37531LOWA cross-site scripting (XSS) vulnerability affects HCL BigFix PlatformEPSS 0.4%CVE-2023-37527MEDIUMA cross-site scripting (XSS) vulnerability affects HCL BigFix PlatformEPSS 0.4%CVE-2021-27758MEDIUMThere is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to loEPSS 0.4%CVE-2023-45718LOWHCL Sametime is impacted by a failure to invalidate sessionsEPSS 0.4%CVE-2026-67100CRITICALHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.4%CVE-2026-56453MEDIUMHCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.EPSS 0.4%CVE-2022-42447CRITICALCross-origin resource sharing vulnerability affects HCL CompassEPSS 0.4%CVE-2020-4083HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a locaEPSS 0.3%CVE-2024-30150MEDIUMAn unauthenticated privilege escalation vulnerability affects HCL MyCloudEPSS 0.3%CVE-2024-23557LOWHCL Connections is vulnerable to a user enumeration vulnerabilityEPSS 0.3%CVE-2021-27782MEDIUMHCL BigFix Mobile / Modern Client Management Server passwords are susceptible to a brute-force attackEPSS 0.3%CVE-2024-23588MEDIUMA denial of service vulnerability affects HCL Nomad server on DominoEPSS 0.3%CVE-2022-42452MEDIUMHCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks suchEPSS 0.3%CVE-2023-28013MEDIUMHCL Verse is susceptible to a Reflected Cross-Site Scripting (XSS) VulnerabilityEPSS 0.3%CVE-2024-42170MEDIUMHCL MyXalytics is affected by a session fixation vulnerabilityEPSS 0.3%CVE-2023-37528MEDIUMA cross-site scripting (XSS) vulnerability affects HCL BigFix PlatformEPSS 0.3%CVE-2022-44758MEDIUMHCL BigFix Insights for Vulnerability Remediation (IVR) is vulnerable to improper credential handlingEPSS 0.3%CVE-2023-37529LOWA cross-site scripting (XSS) vulnerability affects HCL BigFix PlatformEPSS 0.3%CVE-2023-37530LOWA cross-site scripting (XSS) vulnerability affects HCL BigFix PlatformEPSS 0.3%