Filtered by vendor Hcltech
Subscribe
Total
447 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-28008 | 1 Hcltech | 1 Workload Automation | 2026-06-17 | N/A | 7.1 HIGH |
| HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |||||
| CVE-2023-28006 | 1 Hcltech | 1 Bigfix Osd Bare Metal Server | 2026-06-17 | N/A | 7.0 HIGH |
| The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure. | |||||
| CVE-2023-23347 | 1 Hcltech | 1 Dryice Iautomate | 2026-06-17 | N/A | 6.4 MEDIUM |
| HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information. | |||||
| CVE-2023-23346 | 1 Hcltech | 1 Dryice Mycloud | 2026-06-17 | N/A | 6.4 MEDIUM |
| HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information. | |||||
| CVE-2023-23344 | 1 Hcltech | 1 Bigfix Webui Insights | 2026-06-17 | N/A | 3.0 LOW |
| A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page. | |||||
| CVE-2023-23343 | 1 Hcltech | 1 Bigfix Osd Bare Metal Server | 2026-06-17 | N/A | 2.4 LOW |
| A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain. | |||||
| CVE-2023-23342 | 1 Hcltech | 1 Hcl Nomad | 2026-06-17 | N/A | 6.6 MEDIUM |
| If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented. | |||||
| CVE-2022-44760 | 1 Hcltech | 1 Hcl Leap | 2026-06-17 | N/A | 4.6 MEDIUM |
| Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications. | |||||
| CVE-2022-44759 | 1 Hcltech | 1 Hcl Leap | 2026-06-17 | N/A | 4.6 MEDIUM |
| Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications. | |||||
| CVE-2022-44758 | 1 Hcltech | 1 Bigfix Insights For Vulnerability Remediation | 2026-06-17 | N/A | 6.5 MEDIUM |
| BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized. | |||||
| CVE-2022-44757 | 1 Hcltech | 1 Bigfix Insights For Vulnerability Remediation | 2026-06-17 | N/A | 6.5 MEDIUM |
| BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc. | |||||
| CVE-2022-44755 | 1 Hcltech | 1 Notes | 2026-06-17 | N/A | 9.8 CRITICAL |
| HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44751. This vulnerability applies to software previously licensed by IBM. | |||||
| CVE-2022-44754 | 1 Hcltech | 1 Domino | 2026-06-17 | N/A | 9.8 CRITICAL |
| HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44750. This vulnerability applies to software previously licensed by IBM. | |||||
| CVE-2022-44753 | 1 Hcltech | 1 Notes | 2026-06-17 | N/A | 9.8 CRITICAL |
| HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM. | |||||
| CVE-2022-44752 | 1 Hcltech | 1 Domino | 2026-06-17 | N/A | 9.8 CRITICAL |
| HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM. | |||||
| CVE-2022-44751 | 1 Hcltech | 1 Notes | 2026-06-17 | N/A | 9.8 CRITICAL |
| HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755. This vulnerability applies to software previously licensed by IBM. | |||||
| CVE-2022-44750 | 1 Hcltech | 1 Domino | 2026-06-17 | N/A | 9.8 CRITICAL |
| HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44754. This vulnerability applies to software previously licensed by IBM. | |||||
| CVE-2022-42453 | 1 Hcltech | 1 Bigfix Platform | 2026-06-17 | N/A | 6.9 MEDIUM |
| There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script. | |||||
| CVE-2022-42451 | 1 Hcltech | 1 Bigfix Patch Management | 2026-06-17 | N/A | 4.6 MEDIUM |
| Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user. | |||||
| CVE-2022-42450 | 1 Hcltech | 1 Domino Leap | 2026-06-17 | N/A | 4.6 MEDIUM |
| Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications. | |||||
