Hcl
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Hcl product.
RSS Feeds for Hcl security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Hcl products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Hcl Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 123 vulnerabilities in Hcl with an average score of 4.4 out of ten. Last year, in 2025 Hcl had 39 security vulnerabilities published. That is, 84 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.77
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 123 | 4.40 |
| 2025 | 39 | 5.16 |
| 2024 | 5 | 5.60 |
| 2023 | 1 | 5.30 |
It may take a day or so for new Hcl vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Hcl Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2025-62343 | Aug 27, 2026 |
HCL IEM Admin Session Concurrency Allowing Active SessionsHCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session deletion. |
|
| CVE-2025-62342 | Aug 27, 2026 |
HCL IEM Session Deletion Vulnerability (CVE-2025-62342)HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of user sessions, resulting in sessions not being fully terminated after logout or deletion. |
|
| CVE-2026-21754 | Aug 25, 2026 |
HCL Hive Infra Config Enables Lateral Movement & Container BreakoutHCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications. |
|
| CVE-2026-21753 | Aug 25, 2026 |
HCL Hive Supply Chain Vulnerability: Weak Governance Enables Malicious DependenciesHCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment. |
|
| CVE-2026-21758 | Aug 25, 2026 |
HCL Hive Info Disclosure Vulnerability Enabling Host Environment LeakHCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment. |
|
| CVE-2026-21784 | Aug 20, 2026 |
CORS Header Misconfiguration in HCL IntelliOps IEMHCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation. |
|
| CVE-2025-62299 | Aug 20, 2026 |
Least Privileges Violation in HCL IntelliOps IEMHCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges. |
|
| CVE-2025-62300 | Aug 20, 2026 |
Race Condition in HCL IntelliOps IEM Resource ModificationHCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior. |
|
| CVE-2025-62306 | Aug 20, 2026 |
CVE-2025-62306: HCL IEM Logging Omission Breaches Audit TrailHCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response. |
|
| CVE-2025-62307 | Aug 20, 2026 |
IEM Logging Gaps in HCL IntelliOps Facilitate Privilege EscalationHCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing. |
|
| CVE-2026-21832 | Aug 13, 2026 |
HCL AION Indirect Prompt Injection HTML InjectionHCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. |
|
| CVE-2025-62315 | Aug 13, 2026 |
HCL Aion Server-side Input Validation BypassHCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions. |
|
| CVE-2025-62318 | Aug 13, 2026 |
HCL AION JavaScript Hijacking via Referenced ResponsesHCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions. |
|
| CVE-2025-62314 | Aug 13, 2026 |
HCL AION Endpoint Anti-Automation Bypass (CVE-2025-62314)HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions. |
|
| CVE-2025-52640 | Aug 13, 2026 |
HCL AION Shared Storage Access Separation IssueHCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended behavior or security impact under certain conditions. |
|
| CVE-2025-62347 | Jul 31, 2026 |
HCL iControl Improper Input Validation VulnerabilityHCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the received input matches the expected type. |
|
| CVE-2026-56571 | Jul 31, 2026 |
HCL iControl Improper Error Handling Vulnerability (CVE-2026-56571)HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated. |
|
| CVE-2026-56570 | Jul 31, 2026 |
HCL iControl AutoComplete InfoDisclosure via Browser SuggestionHCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions. |
|
| CVE-2026-56569 | Jul 31, 2026 |
Sensitive Data Exposure: Public Exposure of Config Files in HCL iControlHCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. |
|
| CVE-2026-56568 | Jul 31, 2026 |
iControl Info Exposure via Verbose API Error MessagesHCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status |
|
| CVE-2026-56567 | Jul 31, 2026 |
HCL iControl 4.3 Misconfig: Public Exposure of Internal Config FilesHCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. |
|
| CVE-2024-23564 | Jul 17, 2026 |
HCL Aftermarket EPC: Auth Bypass Password Disclosure via Email RequestHCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails. |
|
| CVE-2026-56456 | Jul 16, 2026 |
HCL DFXAnalytics Internal File Path Disclosure via Unhandled ErrorsHCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which could allow a remote attacker to map the underlying server environment and identify targets for further exploitation. |
|
| CVE-2026-56455 | Jul 16, 2026 |
HCL DFXAnalytics Buffer Overflow Can Trigger DoSHCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system to crash or become unresponsive. To mitigate this flaw, comprehensive input length checks must be implemented and enforced on both the client and server sides. |
|
| CVE-2026-56454 | Jul 16, 2026 |
HCL DFXAnalytics Deprecated TLS 1.0/1.1 Usage VulnerabilityHCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and exclusively enable support for secure protocols, specifically TLS 1.2 and TLS 1.3. |
|
| CVE-2026-56453 | Jul 16, 2026 |
HCL DFXAnalytics Account Takeover via Response ManipulationHCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts. |
|
| CVE-2026-35145 | Jul 16, 2026 |
HCL DFXAnalytics Missing HSTS Header Remote MitM VulnerabilityHCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses. |
|
| CVE-2026-35143 | Jul 16, 2026 |
HCL DFXAnalytics Missing SameSite on Session Cookies CSRF RiskHCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF tokens, are not implemented. |
|
| CVE-2026-35142 | Jul 16, 2026 |
HCL DFXAnalytics IP Address Disclosure CVE-2026-35142HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks. |
|
| CVE-2026-35141 | Jul 16, 2026 |
Login Replay Vulnerability in HCL DFXAnalyticsHCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejected by the recipient system. |
|
| CVE-2026-35140 | Jul 16, 2026 |
Missing Secure Attribute on Auth Session Cookie in HCL DFXAnalyticsHCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels. |
|
| CVE-2026-35147 | Jul 16, 2026 |
HCL DFXServer Broken Auth via Direct APIHCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials. |
|
| CVE-2026-35149 | Jul 16, 2026 |
HCL DFXServer Auth Bypass via Server Response ManipHCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification. |
|
| CVE-2026-35148 | Jul 16, 2026 |
Missing Access Control in HCL DFXServer API EndpointsHCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level. |
|
| CVE-2026-9007 | Jul 15, 2026 |
HCL Notes 12.0.2FP5HF8 XSS via Reflected User InputImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (XSS). Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another user. This issue affects HCL Notes: Release 12.0.2FP5HF8 on Linux 4.18.0-553.52.1.El8_10.X64_64#1. |
|
| CVE-2025-59872 | Jun 17, 2026 |
Unrestricted File Upload in HCL ZIE for Web (CVE-2025-59872)HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code |
|
| CVE-2025-62340 | Jun 17, 2026 |
HCL iControl Session Timeout FailureHCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity |
|
| CVE-2025-62338 | Jun 04, 2026 |
HCL BigFix Cloud LC Mgt: Input Validation Flaw Enables Info ExposureHCL BigFix Cloud Lifecycle Management is affected by lack of input validation. This low-level flaw allows unauthorized access and may lead to information exposure. |
|
| CVE-2025-59874 | Jun 04, 2026 |
CSP Directive Missing in HCL Hive Telco Obs Keycloak Web AppHCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable. |
|
| CVE-2025-52606 | Jun 04, 2026 |
HCL iControl Weak Input Validation (WIV) VulnerabilityHCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type. |
|
| CVE-2025-52608 | Jun 04, 2026 |
HCL iControl Missing Cookie Attributes (Secure, SameSite)HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root. |
|
| CVE-2025-52609 | Jun 04, 2026 |
HCL iControl XSS via Missing Security HeadersHCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers. |
|
| CVE-2025-52611 | Jun 04, 2026 |
HCL iControl v4.0.0 stack trace disclosure via undefined JS propertyHCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object that is undefined. This issue likely stems from one of the following: A missing or improperly initialized object. |
|
| CVE-2025-52612 | Jun 04, 2026 |
Reflected XSS via CSV Export in HCL iControlHCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. . |
|
| CVE-2024-42206 | Jun 02, 2026 |
CVE-2024-42206: HCL iReflection Web App Uses Outdated Vulnerable ComponentsHCL iReflection Third party vulnerable and outdated components issue was detected in the web application |
|
| CVE-2025-31985 | May 20, 2026 |
HCL BigFix SM X-Content-Type-Options Header Misconfig - Browser MIME SniffingHCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure X-Content-Type-Options header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly. |
|
| CVE-2025-31973 | May 20, 2026 |
Insecure Base Image Use in HCL BigFix Service ManagementHCL BigFix Service Management (SM) is susceptible to a Configuration 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment. |
|
| CVE-2025-62305 | May 14, 2026 |
OOB Disclosure in HCL AION (CVE-2025-62305)HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allow exposure of data to external systems under specific conditions. |
|
| CVE-2025-62317 | May 14, 2026 |
HCL AION Sensitive Data in URL Parameters DisclosureHCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions. |
|
| CVE-2025-62308 | May 14, 2026 |
Sensitive Backend Info Disclosure in HCL AIONHCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details, which may potentially assist in further analysis or targeted actions under certain conditions |
|