Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Total 449 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-31960 1 Hcltech 1 Bigfix Service Management 2026-06-17 N/A 5.3 MEDIUM
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an unhandled exception.
CVE-2025-31959 1 Hcltech 1 Bigfix Service Management 2026-06-17 N/A 3.5 LOW
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
CVE-2025-31958 1 Hcltech 1 Bigfix Service Management 2026-06-17 N/A 3.7 LOW
HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking.
CVE-2025-31957 1 Hcltech 1 Bigfix Service Management 2026-06-17 N/A 2.6 LOW
HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data.
CVE-2025-31955 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 7.6 HIGH
HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system.
CVE-2025-31954 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 5.4 MEDIUM
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.
CVE-2025-31953 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 7.1 HIGH
HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.
CVE-2025-31952 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 7.1 HIGH
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.
CVE-2025-0279 1 Hcltech 1 Traveler 2026-06-17 N/A 4.3 MEDIUM
HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks.
CVE-2025-0278 1 Hcltech 1 Traveler 2026-06-17 N/A 4.3 MEDIUM
HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests.
CVE-2025-0277 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2026-06-17 N/A 6.5 MEDIUM
HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
CVE-2025-0276 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2026-06-17 N/A 6.5 MEDIUM
HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
CVE-2025-0275 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2026-06-17 N/A 5.3 MEDIUM
HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
CVE-2025-0274 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2026-06-17 N/A 5.3 MEDIUM
HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
CVE-2025-0253 1 Hcltech 1 Intelliops Event Management 2026-06-17 N/A 2.0 LOW
HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential vulnerabilities.
CVE-2025-0252 1 Hcltech 1 Intelliops Event Management 2026-06-17 N/A 2.6 LOW
HCL IEM is affected by a password in cleartext vulnerability.  Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit.
CVE-2025-0251 1 Hcltech 1 Intelliops Event Management 2026-06-17 N/A 2.6 LOW
HCL IEM is affected by a concurrent login vulnerability.  The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks.
CVE-2025-0250 1 Hcltech 1 Intelliops Event Management 2026-06-17 N/A 2.2 LOW
HCL IEM is affected by an authorization token sent in cookie vulnerability.  A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks.
CVE-2025-0249 1 Hcltech 1 Intelliops Event Management 2026-06-17 N/A 3.3 LOW
HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.  A token was not invalidated which may allow attackers to access sensitive data without authorization.
CVE-2024-42213 1 Hcltech 1 Bigfix Compliance 2026-06-17 N/A 5.3 MEDIUM
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.