Filtered by vendor Hcltech
Subscribe
Total
449 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-31997 | 1 Hcltech | 1 Unica Centralized Offer Management | 2026-06-17 | N/A | 4.2 MEDIUM |
| HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files. | |||||
| CVE-2025-31996 | 1 Hcltech | 1 Unica | 2026-06-17 | N/A | 5.3 MEDIUM |
| HCL Unica Platform is affected by unprotected files due to improper access controls. These files may contain sensitive information such as private or system information that can be exploited by attackers to compromise the application, infrastructure, or users. | |||||
| CVE-2025-31993 | 1 Hcltech | 1 Unica Centralized Offer Management | 2026-06-17 | N/A | 3.5 LOW |
| HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can exploit improper input validation by submitting maliciously crafted input to a target application running on a server. | |||||
| CVE-2025-31988 | 1 Hcltech | 1 Digital Experience | 2026-06-17 | N/A | 4.9 MEDIUM |
| HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access. | |||||
| CVE-2025-31987 | 1 Hcltech | 1 Connections Docs | 2026-06-17 | N/A | 4.8 MEDIUM |
| HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion. | |||||
| CVE-2025-31984 | 1 Hcltech | 1 Bigfix Service Management | 2026-06-17 | N/A | 3.7 LOW |
| HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly. | |||||
| CVE-2025-31983 | 1 Hcltech | 1 Bigfix Service Management | 2026-06-17 | N/A | 3.7 LOW |
| HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers to inject malicious scripts increasing the risk of cross-site scripting (XSS) and potential exposure of sensitive information. | |||||
| CVE-2025-31982 | 1 Hcltech | 1 Bigfix Service Management | 2026-06-17 | N/A | 3.7 LOW |
| HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk of information disclosure or misuse of sensitive functionality. | |||||
| CVE-2025-31981 | 1 Hcltech | 1 Bigfix Service Management | 2026-06-17 | N/A | 5.3 MEDIUM |
| HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. An attacker with access to the network traffic can sniff packets from the connection and uncover the data. | |||||
| CVE-2025-31977 | 1 Hcltech | 1 Bigfix Service Management | 2026-06-17 | N/A | 5.3 MEDIUM |
| HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms. An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions. | |||||
| CVE-2025-31975 | 1 Hcltech | 1 Bigfix Service Management | 2026-06-17 | N/A | 2.6 LOW |
| HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal software versions and system details, potentially aiding attackers in targeting known vulnerabilities. | |||||
| CVE-2025-31974 | 1 Hcltech | 1 Bigfix Service Management | 2026-06-17 | N/A | 3.9 LOW |
| HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modifications to critical system components, potentially increasing the risk of system compromise or unauthorized changes. | |||||
| CVE-2025-31972 | 1 Hcltech | 1 Bigfix Service Management | 2026-06-17 | N/A | 6.5 MEDIUM |
| HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components. | |||||
| CVE-2025-31970 | 1 Hcltech | 1 Dfxanalytics | 2026-06-17 | N/A | 5.3 MEDIUM |
| HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection vectors such as Cross-Site Scripting (XSS) | |||||
| CVE-2025-31969 | 1 Hcltech | 1 Unica | 2026-06-17 | N/A | 4.0 MEDIUM |
| HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking. | |||||
| CVE-2025-31966 | 1 Hcltech | 1 Sametime | 2026-06-17 | N/A | 2.7 LOW |
| HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server. | |||||
| CVE-2025-31964 | 1 Hcltech | 1 Bigfix Insights For Vulnerability Remediation | 2026-06-17 | N/A | 2.2 LOW |
| Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface. | |||||
| CVE-2025-31963 | 1 Hcltech | 1 Bigfix Insights For Vulnerability Remediation | 2026-06-17 | N/A | 2.9 LOW |
| Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests. | |||||
| CVE-2025-31962 | 1 Hcltech | 1 Bigfix Insights For Vulnerability Remediation | 2026-06-17 | N/A | 2.0 LOW |
| Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods. | |||||
| CVE-2025-31961 | 1 Hcltech | 1 Connections | 2026-06-17 | N/A | 3.7 LOW |
| HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios. | |||||
