Vulnerabilidades em HCL Software

384 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2024-42189MEDIUMHCL BigFix Web Reports might be subject to a Denial of Service (DoS) attackEPSS 0.3%CVE-2021-27759LOWThis vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was seEPSS 0.3%CVE-2024-42213MEDIUMHCL BigFix Compliance is affected by inclusion of temporary files left in the production environmentEPSS 0.3%CVE-2023-45721MEDIUMHCL Domino Volt and Domino Leap are affected by a disclosure of private personal information vulnerabilityEPSS 0.3%CVE-2024-23564CRITICALHCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from thEPSS 0.3%CVE-2025-59873MEDIUMSession Token Exposure via URL Query ParametersEPSS 0.3%CVE-2025-0279MEDIUMHCL Traveler is affected by generation of error messages containing sensitive informationEPSS 0.3%CVE-2025-0278MEDIUMAn internal path disclosure vulnerability affects HCL TravelerEPSS 0.3%CVE-2022-38653LOWHCL Digital Experience is susceptible to cross-site scripting (XSS)EPSS 0.3%CVE-2025-0254MEDIUMHCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226.EPSS 0.3%CVE-2023-37504HIGHAn insufficient session expiration vulnerability affects HCL CompassEPSS 0.3%CVE-2023-50342HIGHInsecure Direct Object Reference (IDOR) affects DRYiCE MyXalyticsEPSS 0.3%CVE-2020-4099MEDIUMHCL Verse for Android is susceptible to an APK signing key check vulnerabilityEPSS 0.3%CVE-2024-42195LOWHCL DevOps Deploy / HCL Launch is vulnerable to HTML injectionEPSS 0.3%CVE-2025-31955HIGHHCL iAutomate is affected by a sensitive data exposure vulnerabilityEPSS 0.3%CVE-2022-38657HIGHAn open redirect to malicious sites affects HCL LeapEPSS 0.3%CVE-2024-30130LOWHCL Nomad server on Domino is affected by a use of web browser cache containing sensitive information vulnerabilityEPSS 0.3%CVE-2022-44760MEDIUMHCL Leap is affected by an unrestricted upload of file with dangerous type vulnerabilityEPSS 0.3%CVE-2024-42175LOWHCL MyXalytics is affected by a weak input validation vulnerabilityEPSS 0.3%CVE-2024-23584MEDIUMHCL BigFix Asset Discovery is affected by a security vulnerabilityEPSS 0.3%