Filtered by vendor Hcltech
Subscribe
Total
442 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-15633 | 1 Hcltech | 21 Bigfix Webui Api, Bigfix Webui Application Administration, Bigfix Webui Cmep and 18 more | 2026-07-25 | N/A | 6.5 MEDIUM |
| An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers. | |||||
| CVE-2025-31985 | 1 Hcltech | 1 Bigfix Service Management | 2026-07-24 | N/A | 3.7 LOW |
| HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly. | |||||
| CVE-2025-31973 | 1 Hcltech | 1 Bigfix Service Management | 2026-07-24 | N/A | 4.0 MEDIUM |
| HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment. | |||||
| CVE-2026-21826 | 1 Hcltech | 2 Digital Experience, Digital Experience Compose | 2026-07-23 | N/A | 6.1 MEDIUM |
| HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways. | |||||
| CVE-2026-21837 | 1 Hcltech | 2 Digital Experience, Digital Experience Compose | 2026-07-23 | N/A | 8.8 HIGH |
| HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise. | |||||
| CVE-2026-21825 | 1 Hcltech | 2 Digital Experience, Digital Experience Compose | 2026-07-23 | N/A | 6.1 MEDIUM |
| HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser. | |||||
| CVE-2025-52611 | 1 Hcltech | 1 Icontrol | 2026-07-22 | N/A | 3.1 LOW |
| HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object that is undefined. This issue likely stems from one of the following: A missing or improperly initialized object. | |||||
| CVE-2025-52612 | 1 Hcltech | 1 Icontrol | 2026-07-22 | N/A | 7.1 HIGH |
| HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. . | |||||
| CVE-2025-52609 | 1 Hcltech | 1 Icontrol | 2026-07-22 | N/A | 3.7 LOW |
| HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers. | |||||
| CVE-2025-52606 | 1 Hcltech | 1 Icontrol | 2026-07-22 | N/A | 4.3 MEDIUM |
| HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type. | |||||
| CVE-2025-52608 | 1 Hcltech | 1 Icontrol | 2026-07-22 | N/A | 3.1 LOW |
| HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root. | |||||
| CVE-2026-35149 | 1 Hcltech | 1 Dfx Server | 2026-07-21 | N/A | 8.2 HIGH |
| HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification. | |||||
| CVE-2026-35148 | 1 Hcltech | 1 Dfx Server | 2026-07-21 | N/A | 6.3 MEDIUM |
| HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level. | |||||
| CVE-2026-35147 | 1 Hcltech | 1 Dfx Server | 2026-07-21 | N/A | 8.2 HIGH |
| HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials. | |||||
| CVE-2026-35146 | 1 Hcltech | 1 Dfx Server | 2026-07-21 | N/A | 6.3 MEDIUM |
| HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application. | |||||
| CVE-2026-56456 | 1 Hcltech | 1 Dfxanalytics | 2026-07-17 | N/A | 5.3 MEDIUM |
| HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which could allow a remote attacker to map the underlying server environment and identify targets for further exploitation. | |||||
| CVE-2026-56455 | 1 Hcltech | 1 Dfxanalytics | 2026-07-17 | N/A | 5.3 MEDIUM |
| HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system to crash or become unresponsive. To mitigate this flaw, comprehensive input length checks must be implemented and enforced on both the client and server sides. | |||||
| CVE-2026-56454 | 1 Hcltech | 1 Dfxanalytics | 2026-07-17 | N/A | 5.9 MEDIUM |
| HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and exclusively enable support for secure protocols, specifically TLS 1.2 and TLS 1.3. | |||||
| CVE-2026-56453 | 1 Hcltech | 1 Dfxanalytics | 2026-07-17 | N/A | 5.5 MEDIUM |
| HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts. | |||||
| CVE-2026-35145 | 1 Hcltech | 1 Dfxanalytics | 2026-07-17 | N/A | 3.1 LOW |
| HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses. | |||||
