Hcl Hcl

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Hcl product.

RSS Feeds for Hcl security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Hcl products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Hcl Sorted by Most Security Vulnerabilities since 2018

Hcl Aion43 vulnerabilities

Hcl Bigfix27 vulnerabilities

Hcl Unica13 vulnerabilities

Hcl Myxalytics7 vulnerabilities

Hcl Devops Loop1 vulnerability

Hcl Domino Appdev Pack1 vulnerability

Hcl Iautomate1 vulnerability

By the Year

In 2026 there have been 123 vulnerabilities in Hcl with an average score of 4.4 out of ten. Last year, in 2025 Hcl had 39 security vulnerabilities published. That is, 84 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.77




Year Vulnerabilities Average Score
2026 123 4.40
2025 39 5.16
2024 5 5.60
2023 1 5.30

It may take a day or so for new Hcl vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Hcl Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2025-62343 Aug 27, 2026
HCL IEM Admin Session Concurrency Allowing Active Sessions HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session deletion.
CVE-2025-62342 Aug 27, 2026
HCL IEM Session Deletion Vulnerability (CVE-2025-62342) HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of user sessions, resulting in sessions not being fully terminated after logout or deletion.
CVE-2026-21754 Aug 25, 2026
HCL Hive Infra Config Enables Lateral Movement & Container Breakout HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications.
CVE-2026-21753 Aug 25, 2026
HCL Hive Supply Chain Vulnerability: Weak Governance Enables Malicious Dependencies HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.
CVE-2026-21758 Aug 25, 2026
HCL Hive Info Disclosure Vulnerability Enabling Host Environment Leak HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment.
CVE-2026-21784 Aug 20, 2026
CORS Header Misconfiguration in HCL IntelliOps IEM HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation.
CVE-2025-62299 Aug 20, 2026
Least Privileges Violation in HCL IntelliOps IEM HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.
CVE-2025-62300 Aug 20, 2026
Race Condition in HCL IntelliOps IEM Resource Modification HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior.
CVE-2025-62306 Aug 20, 2026
CVE-2025-62306: HCL IEM Logging Omission Breaches Audit Trail HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.
CVE-2025-62307 Aug 20, 2026
IEM Logging Gaps in HCL IntelliOps Facilitate Privilege Escalation HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.
CVE-2026-21832 Aug 13, 2026
HCL AION Indirect Prompt Injection HTML Injection HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.
Aion
CVE-2025-62315 Aug 13, 2026
HCL Aion Server-side Input Validation Bypass HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions.
Aion
CVE-2025-62318 Aug 13, 2026
HCL AION JavaScript Hijacking via Referenced Responses HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.
Aion
CVE-2025-62314 Aug 13, 2026
HCL AION Endpoint Anti-Automation Bypass (CVE-2025-62314) HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.
Aion
CVE-2025-52640 Aug 13, 2026
HCL AION Shared Storage Access Separation Issue HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended behavior or security impact under certain conditions.
Aion
CVE-2025-62347 Jul 31, 2026
HCL iControl Improper Input Validation Vulnerability HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the received input matches the expected type.
CVE-2026-56571 Jul 31, 2026
HCL iControl Improper Error Handling Vulnerability (CVE-2026-56571) HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated.
CVE-2026-56570 Jul 31, 2026
HCL iControl AutoComplete InfoDisclosure via Browser Suggestion HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions.
CVE-2026-56569 Jul 31, 2026
Sensitive Data Exposure: Public Exposure of Config Files in HCL iControl HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
CVE-2026-56568 Jul 31, 2026
iControl Info Exposure via Verbose API Error Messages HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status
CVE-2026-56567 Jul 31, 2026
HCL iControl 4.3 Misconfig: Public Exposure of Internal Config Files HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
CVE-2024-23564 Jul 17, 2026
HCL Aftermarket EPC: Auth Bypass Password Disclosure via Email Request HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.
CVE-2026-56456 Jul 16, 2026
HCL DFXAnalytics Internal File Path Disclosure via Unhandled Errors HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which could allow a remote attacker to map the underlying server environment and identify targets for further exploitation.
CVE-2026-56455 Jul 16, 2026
HCL DFXAnalytics Buffer Overflow Can Trigger DoS HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system to crash or become unresponsive. To mitigate this flaw, comprehensive input length checks must be implemented and enforced on both the client and server sides.
CVE-2026-56454 Jul 16, 2026
HCL DFXAnalytics Deprecated TLS 1.0/1.1 Usage Vulnerability HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and exclusively enable support for secure protocols, specifically TLS 1.2 and TLS 1.3.
CVE-2026-56453 Jul 16, 2026
HCL DFXAnalytics Account Takeover via Response Manipulation HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts.
CVE-2026-35145 Jul 16, 2026
HCL DFXAnalytics Missing HSTS Header Remote MitM Vulnerability HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.
CVE-2026-35143 Jul 16, 2026
HCL DFXAnalytics Missing SameSite on Session Cookies CSRF Risk HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF tokens, are not implemented.
CVE-2026-35142 Jul 16, 2026
HCL DFXAnalytics IP Address Disclosure CVE-2026-35142 HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.
CVE-2026-35141 Jul 16, 2026
Login Replay Vulnerability in HCL DFXAnalytics HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejected by the recipient system.
CVE-2026-35140 Jul 16, 2026
Missing Secure Attribute on Auth Session Cookie in HCL DFXAnalytics HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.
CVE-2026-35147 Jul 16, 2026
HCL DFXServer Broken Auth via Direct API HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials.
CVE-2026-35149 Jul 16, 2026
HCL DFXServer Auth Bypass via Server Response Manip HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.
CVE-2026-35148 Jul 16, 2026
Missing Access Control in HCL DFXServer API Endpoints HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.
CVE-2026-9007 Jul 15, 2026
HCL Notes 12.0.2FP5HF8 XSS via Reflected User Input Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (XSS).  Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another user. This issue affects HCL Notes: Release 12.0.2FP5HF8 on Linux 4.18.0-553.52.1.El8_10.X64_64#1.
CVE-2025-59872 Jun 17, 2026
Unrestricted File Upload in HCL ZIE for Web (CVE-2025-59872) HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code
CVE-2025-62340 Jun 17, 2026
HCL iControl Session Timeout Failure HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
CVE-2025-62338 Jun 04, 2026
HCL BigFix Cloud LC Mgt: Input Validation Flaw Enables Info Exposure HCL BigFix Cloud Lifecycle Management is affected by lack of input validation.  This low-level flaw allows unauthorized access and may lead to information exposure.
Bigfix
CVE-2025-59874 Jun 04, 2026
CSP Directive Missing in HCL Hive Telco Obs Keycloak Web App HCL Hive Telco Observability is affected by  a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable.
CVE-2025-52606 Jun 04, 2026
HCL iControl Weak Input Validation (WIV) Vulnerability HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
CVE-2025-52608 Jun 04, 2026
HCL iControl Missing Cookie Attributes (Secure, SameSite) HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.
CVE-2025-52609 Jun 04, 2026
HCL iControl XSS via Missing Security Headers HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers.
CVE-2025-52611 Jun 04, 2026
HCL iControl v4.0.0 stack trace disclosure via undefined JS property HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object that is undefined. This issue likely stems from one of the following: A missing or improperly initialized object.
CVE-2025-52612 Jun 04, 2026
Reflected XSS via CSV Export in HCL iControl HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .
CVE-2024-42206 Jun 02, 2026
CVE-2024-42206: HCL iReflection Web App Uses Outdated Vulnerable Components HCL iReflection Third party vulnerable and outdated components issue was detected in the web application
CVE-2025-31985 May 20, 2026
HCL BigFix SM X-Content-Type-Options Header Misconfig - Browser MIME Sniffing HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure X-Content-Type-Options header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly.
Bigfix
CVE-2025-31973 May 20, 2026
Insecure Base Image Use in HCL BigFix Service Management HCL BigFix Service Management (SM) is susceptible to a Configuration 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.
Bigfix
CVE-2025-62305 May 14, 2026
OOB Disclosure in HCL AION (CVE-2025-62305) HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allow exposure of data to external systems under specific conditions.
Aion
CVE-2025-62317 May 14, 2026
HCL AION Sensitive Data in URL Parameters Disclosure HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions.
Aion
CVE-2025-62308 May 14, 2026
Sensitive Backend Info Disclosure in HCL AION HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details, which may potentially assist in further analysis or targeted actions under certain conditions
Aion
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.