Filtered by vendor Hcltech
Subscribe
Total
442 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-35140 | 1 Hcltech | 1 Dfxanalytics | 2026-07-17 | N/A | 3.0 LOW |
| HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels. | |||||
| CVE-2026-35141 | 1 Hcltech | 1 Dfxanalytics | 2026-07-17 | N/A | 2.6 LOW |
| HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejected by the recipient system. | |||||
| CVE-2026-35142 | 1 Hcltech | 1 Dfxanalytics | 2026-07-17 | N/A | 2.6 LOW |
| HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks. | |||||
| CVE-2026-35143 | 1 Hcltech | 1 Dfxanalytics | 2026-07-17 | N/A | 3.0 LOW |
| HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF tokens, are not implemented. | |||||
| CVE-2025-31991 | 1 Hcltech | 1 Devops Velocity | 2026-07-07 | N/A | 6.8 MEDIUM |
| Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit. This vulnerability is fixed in 5.1.7. | |||||
| CVE-2024-23581 | 1 Hcltech | 1 Traveler For Microsoft Outlook | 2026-07-06 | N/A | 6.7 MEDIUM |
| The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application. | |||||
| CVE-2023-37524 | 1 Hcltech | 1 Traveler For Microsoft Outlook | 2026-07-06 | N/A | 7.7 HIGH |
| HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party components. | |||||
| CVE-2025-59868 | 1 Hcltech | 1 Traveler For Microsoft Outlook | 2026-07-06 | N/A | 5.5 MEDIUM |
| HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application. | |||||
| CVE-2025-63402 | 1 Hcltech | 1 Dragon | 2026-07-05 | N/A | 5.5 MEDIUM |
| An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests | |||||
| CVE-2025-63401 | 1 Hcltech | 1 Dragon | 2026-07-05 | N/A | 5.5 MEDIUM |
| Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives | |||||
| CVE-2025-31978 | 1 Hcltech | 1 Bigfix Service Management | 2026-06-29 | N/A | 4.6 MEDIUM |
| HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other malicious activity when automatically executed by the spreadsheet software. Note that current versions of Excel warn users of untrusted content. | |||||
| CVE-2025-31976 | 1 Hcltech | 1 Bigfix Service Management | 2026-06-29 | N/A | 4.8 MEDIUM |
| HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrated. . | |||||
| CVE-2025-59872 | 1 Hcltech | 1 Zie For Web | 2026-06-26 | N/A | 4.3 MEDIUM |
| HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code | |||||
| CVE-2025-62340 | 1 Hcltech | 1 Icontrol | 2026-06-26 | N/A | 3.1 LOW |
| HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity | |||||
| CVE-2026-21791 | 1 Hcltech | 1 Sametime | 2026-06-17 | N/A | 3.3 LOW |
| HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URL | |||||
| CVE-2026-21788 | 1 Hcltech | 1 Connections | 2026-06-17 | N/A | 5.4 MEDIUM |
| HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may allow the attacker steal cookie-based authentication credentials and comprise user's account then launch other attacks. | |||||
| CVE-2026-21786 | 1 Hcltech | 1 Sametime | 2026-06-17 | N/A | 3.3 LOW |
| HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs. | |||||
| CVE-2026-21783 | 1 Hcltech | 1 Traveler | 2026-06-17 | N/A | 4.3 MEDIUM |
| HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks. | |||||
| CVE-2026-21767 | 1 Hcltech | 1 Bigfix Platform | 2026-06-17 | N/A | 4.0 MEDIUM |
| HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive areas of the application without proper authentication. | |||||
| CVE-2026-21765 | 1 Hcltech | 1 Bigfix Platform | 2026-06-17 | N/A | 8.8 HIGH |
| HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions. | |||||
