Vulnerabilidades em HCL

89 resultados
Análise Vexday

O portfólio de vulnerabilidades da HCL reúne 88 CVEs catalogadas, com volume recente relevante — 32 entradas nos últimos 90 dias —, sinalizando atividade contínua de descoberta e divulgação. Apesar disso, o risco operacional imediato é baixo: nenhuma CVE consta no catálogo KEV da CISA, taxa inferior à média geral do catálogo, e nenhuma prova de conceito pública foi identificada. A falha mais frequente é CWE-200 (exposição indevida de informações), padrão que costuma favorecer reconhecimento e coleta de dados sensíveis quando combinado a outras fraquezas. A CVE mais perigosa atualmente monitorada, CVE-2020-14258, apresenta EPSS de 0,0125, indicando probabilidade de exploração ativa baixa, mas sua antiguidade reforça a importância de verificar se os ativos afetados receberam as correções devidas.

CVE-2024-42206LOWHCL iReflection Use of Third party vulnerable and outdated components issue was detected in the web application.EPSS 0.2%CVE-2025-52632MEDIUMHCL AION is susceptible to Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerabilityEPSS 0.1%CVE-2025-31970MEDIUMHCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerabilityEPSS 0.1%CVE-2025-52646LOWHCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries.EPSS 0.1%CVE-2025-52636LOWHCL AION is affected by a improper handling of uploads files SizeEPSS 0.1%CVE-2025-52644MEDIUMHCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged.EPSS 0.1%CVE-2025-62312LOWHCL AION is affected by a vulnerability where basic authorization tokens are used for authenticationEPSS 0.1%CVE-2025-31984LOWHCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” headerEPSS 0.1%CVE-2026-21791LOWHCL Sametime for Android is affected by sensitive information disclosureEPSS 0.1%CVE-2025-52649LOWHCL AION is affected by a vulnerability where certain identifiers may be predictable in natureEPSS 0.1%CVE-2025-52629LOWHCL AION is susceptible to Missing Content-Security-PolicyEPSS 0.1%CVE-2025-52638MEDIUMMultiple security vulnerabilities affect HCL AIONEPSS 0.1%CVE-2025-59854LOWHCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerabilityEPSS 0.1%CVE-2025-31983LOWHCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP headerEPSS 0.1%CVE-2025-55264MEDIUMHCL Aftermarket DPC is affected by Failure to Invalidate Session on Password ChangeEPSS 0.1%CVE-2025-52648MEDIUMHCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverifieEPSS 0.1%CVE-2025-52641LOWInternal Filesystem Exploration vulnerabilityEPSS 0.1%CVE-2025-62317LOWHCL AION is affected by a vulnerability where sensitive information may be included in URL parameters.EPSS 0.1%CVE-2025-62309LOWHCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields.EPSS 0.1%CVE-2025-62308MEDIUMHCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposedEPSS 0.1%