Vulnerabilidades em HCL Software

384 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2021-27765MEDIUMHCL BigFix Platform Server API is affected by Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-35141LOWHCL DFXAnalytics is affected by a Login Replay Attack vulnerabilityEPSS 0.3%CVE-2025-52618MEDIUMHCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerabilityEPSS 0.3%CVE-2022-44757MEDIUMHCL BigFix Insights for Vulnerability Remediation (IVR) is vulnerable to weak cryptographyEPSS 0.3%CVE-2023-37541LOWHCL Connections is vulnerable to broken access controlEPSS 0.3%CVE-2024-30107LOWHCL Connections is vulnerable to broken access controlEPSS 0.3%CVE-2024-30135LOWSensitive Information Disclosure vulnerability affects DRYiCE AEX v10EPSS 0.3%CVE-2022-27545MEDIUMHCL BigFix Web Reports authorized users may perform HTML injection.EPSS 0.3%CVE-2023-37521LOWHCL BigFix OSD Bare Metal Server WebUI is affected by sensitive information disclosureEPSS 0.3%CVE-2025-52660LOWHCL AION is affected by an Host Header Injection vulnerabilityEPSS 0.3%CVE-2025-31952HIGHHCL iAutomate is affected by an insufficient session expirationEPSS 0.3%CVE-2024-23560MEDIUMHCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom type EPSS 0.3%CVE-2024-23586MEDIUMAn insufficient session timeout vulnerability affects HCL Nomad server on DominoEPSS 0.3%CVE-2021-27768MEDIUMAn SSL certificate host verification vulnerability affects HCL Verse for AndroidEPSS 0.3%CVE-2024-30111LOWMissing Root Detection vulnerability affects DRYiCE AEX v10EPSS 0.3%CVE-2023-45698MEDIUMHCL Sametime is impacted by clickjackingEPSS 0.3%CVE-2023-23343LOWHCL BigFix OSD Bare Metal Server version 311.12 or lower is affected by a clickjacking vulnerability.EPSS 0.3%CVE-2023-28018MEDIUMHCL Connections s vulnerable to possible denial of service for certain usersEPSS 0.3%CVE-2023-50348LOWImproper Error Handling affects DRYiCE MyXalyticsEPSS 0.3%CVE-2024-30141MEDIUMHCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive informationEPSS 0.3%