Hcltech Hcltech

Do you want an email whenever new security vulnerabilities are reported in any Hcltech product?

Products by Hcltech Sorted by Most Security Vulnerabilities since 2018

Hcltech Domino17 vulnerabilities

Hcltech Notes10 vulnerabilities

Hcltech Bigfix Platform10 vulnerabilities

Hcltech Hcl Inotes7 vulnerabilities

Hcltech Appscan6 vulnerabilities

Hcltech Sametime6 vulnerabilities

Hcltech Connections5 vulnerabilities

Hcltech Digital Experience5 vulnerabilities

Hcltech Bigfix Mobile4 vulnerabilities

Hcltech Versionvault Express3 vulnerabilities

Hcltech Verse3 vulnerabilities

Hcltech Traveler3 vulnerabilities

Hcltech Hcl Domino2 vulnerabilities

Hcltech Appscan Source2 vulnerabilities

Hcltech Traveler Companion2 vulnerabilities

Hcltech Bigfix Inventory2 vulnerabilities

Hcltech Hcl Sametime2 vulnerabilities

Hcltech Bigfix Webui2 vulnerabilities

Hcltech Hcl Nomad1 vulnerability

Hcltech Onetest Server1 vulnerability

Hcltech Hcl Leap1 vulnerability

Hcltech Bigfix Insights1 vulnerability

Hcltech Unica1 vulnerability

Hcltech Bigfix Compliance1 vulnerability

By the Year

In 2023 there have been 3 vulnerabilities in Hcltech with an average score of 6.3 out of ten. Last year Hcltech had 51 security vulnerabilities published. Right now, Hcltech is on track to have less security vulnerabilities in 2023 than it did last year. Last year, the average CVE base score was greater by 0.51

Year Vulnerabilities Average Score
2023 3 6.33
2022 51 6.85
2021 5 5.26
2020 37 6.97
2019 3 5.77
2018 0 0.00

It may take a day or so for new Hcltech vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Hcltech Security Vulnerabilities

HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability

CVE-2021-27788 6.1 - Medium - March 10, 2023

HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability. By tricking a user into clicking a crafted URL, a remote unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.

XSS

An open redirect to malicious sites

CVE-2022-38657 5.4 - Medium - February 12, 2023

An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.

Open Redirect

HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced

CVE-2021-27782 7.5 - High - January 20, 2023

HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.

Improper Restriction of Excessive Authentication Attempts

BigFix WebUI non-master operators are missing controls

CVE-2022-38655 5.8 - Medium - December 21, 2022

BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.

In HCL Digital Experience, customized XSS payload can be constructed such

CVE-2022-38653 5.4 - Medium - December 19, 2022

In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.

XSS

In HCL Digital Experience, URLs

CVE-2022-38662 6.1 - Medium - December 19, 2022

In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.

Open Redirect

There are insufficient warnings when a Fixlet is imported by a user

CVE-2022-42453 6.5 - Medium - December 19, 2022

There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.

authentification

HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView

CVE-2022-44754 7.8 - High - December 19, 2022

HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44750. This vulnerability applies to software previously licensed by IBM.

Memory Corruption

HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView

CVE-2022-44753 7.8 - High - December 19, 2022

HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM.

Memory Corruption

HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView

CVE-2022-44752 7.8 - High - December 19, 2022

HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM.

Memory Corruption

HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView

CVE-2022-44751 7.8 - High - December 19, 2022

HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755. This vulnerability applies to software previously licensed by IBM.

Memory Corruption

HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView

CVE-2022-44750 7.8 - High - December 19, 2022

HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44754. This vulnerability applies to software previously licensed by IBM.

Memory Corruption

HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView

CVE-2022-44755 7.8 - High - December 19, 2022

HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44751. This vulnerability applies to software previously licensed by IBM.

Memory Corruption

Starting with Sametime 12, anonymous users are enabled by default

CVE-2022-42446 6.5 - Medium - December 12, 2022

Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users.

Incorrect Default Permissions

HCL Domino is susceptible to an information disclosure vulnerability

CVE-2022-38654 5.5 - Medium - November 04, 2022

HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a user's person record.

HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability

CVE-2022-38660 8.8 - High - November 04, 2022

HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.

Session Riding

The application was signed using a key length less than or equal to 1024 bits

CVE-2020-4099 7.5 - High - November 01, 2022

The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.

Inadequate Encryption Strength

The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key

CVE-2021-27784 7.5 - High - October 31, 2022

The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.

Use of a Broken or Risky Cryptographic Algorithm

User input included in error response

CVE-2021-27774 5.4 - Medium - September 22, 2022

User input included in error response, which could be used in a phishing attack.

Improper Input Validation

There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).

CVE-2022-27561 4.8 - Medium - September 15, 2022

There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).

XSS

HCL VersionVault Express exposes administrator credentials.

CVE-2022-27560 6.5 - Medium - August 30, 2022

HCL VersionVault Express exposes administrator credentials.

Insufficiently Protected Credentials

An unauthenticated user can overload a part of HCL VersionVault Express

CVE-2022-27563 7.5 - High - August 30, 2022

An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.

Improper Check for Unusual or Exceptional Conditions

HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability

CVE-2022-27558 7.5 - High - August 29, 2022

HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.

Weak Password Requirements

HCL iNotes is susceptible to a link to non-existent domain vulnerability

CVE-2022-27547 7.4 - High - August 29, 2022

HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.

Open Redirect

HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request

CVE-2022-27546 6.1 - Medium - August 29, 2022

HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.

XSS

BigFix Web Reports authorized users may see SMTP credentials in clear text.

CVE-2022-27544 6.5 - Medium - July 19, 2022

BigFix Web Reports authorized users may see SMTP credentials in clear text.

Insufficiently Protected Credentials

BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.

CVE-2022-27545 5.4 - Medium - July 19, 2022

BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.

XSS

Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner

CVE-2021-27786 9.8 - Critical - June 09, 2022

Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.

Incorrect Comparison

HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages

CVE-2021-27778 4.8 - Medium - June 01, 2022

HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.

XSS

The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.

CVE-2021-27780 5.3 - Medium - May 27, 2022

The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.

The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.

CVE-2021-27781 4.8 - Medium - May 27, 2022

The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.

XSS

VersionVault Express exposes sensitive information

CVE-2021-27779 9.1 - Critical - May 25, 2022

VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.

Missing Encryption of Sensitive Data

User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.

CVE-2021-27783 6.5 - Medium - May 25, 2022

User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.

Missing Encryption of Sensitive Data

HCL Domino is affected by an Insufficient Access Control vulnerability

CVE-2020-4107 7.8 - High - May 19, 2022

HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure.

Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system

CVE-2021-27769 5.3 - Medium - May 12, 2022

Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any information that could be used for an attack should be limited whenever possible.

The vulnerability was discovered within the FaviconService

CVE-2021-27770 8.8 - High - May 12, 2022

The vulnerability was discovered within the FaviconService. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the meetings-function where users can specify an external URL where the online meeting will take place.

Exposure of Resource to Wrong Sphere

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service

CVE-2021-27771 7.6 - High - May 12, 2022

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.

Unrestricted File Upload

Using the ability to perform a Man-in-the-Middle (MITM) attack

CVE-2021-27768 5.9 - Medium - May 12, 2022

Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in 'transparent' mode while a certificate with an invalid hostname was active. The Android application was found to have hostname verification issues during the server setup and login flows; however, the application did not process requests post-login.

Improper Certificate Validation

Users are able to read group conversations without actively taking part in them

CVE-2021-27772 6.5 - Medium - May 12, 2022

Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it. This could lead to information leakage where confidential information discussed in private groups is read by other users without the users knowledge.

This vulnerability allows users to execute a clickjacking attack in the meeting's chat.

CVE-2021-27773 4.3 - Medium - May 12, 2022

This vulnerability allows users to execute a clickjacking attack in the meeting's chat.

Clickjacking

XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation

CVE-2021-27777 7.5 - High - May 12, 2022

XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.

XXE

The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability

CVE-2021-27766 7.8 - High - May 06, 2022

The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.

Improper Privilege Management

The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability

CVE-2021-27765 7.8 - High - May 06, 2022

The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.

Improper Privilege Management

This vulnerability arises because the application allows the user to perform some sensitive action without verifying

CVE-2021-27759 6.5 - Medium - May 06, 2022

This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.

Insufficient Verification of Data Authenticity

There is a security vulnerability in login form related to Cross-site Request Forgery

CVE-2021-27758 6.5 - Medium - May 06, 2022

There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.

Session Riding

Cookie without HTTPONLY flag set

CVE-2021-27764 6.5 - Medium - May 06, 2022

Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)

Missing Encryption of Sensitive Data

Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses

CVE-2021-27762 9.8 - Critical - May 06, 2022

Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses

Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks

CVE-2021-27761 7.5 - High - May 06, 2022

Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks

Inadequate Encryption Strength

An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients

CVE-2021-27760 5.5 - Medium - May 06, 2022

An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.

The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability

CVE-2021-27767 7.8 - High - May 06, 2022

The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.

Improper Privilege Management

"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5

CVE-2021-27756 7.5 - High - March 04, 2022

"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."

Use of a Broken or Risky Cryptographic Algorithm

" Insecure password storage issue.The application stores sensitive information in cleartext within a resource

CVE-2021-27757 7.5 - High - March 04, 2022

" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive information."

Cleartext Storage of Sensitive Information

"Sametime Android PathTraversal Vulnerability"

CVE-2021-27753 5.5 - Medium - February 21, 2022

"Sametime Android PathTraversal Vulnerability"

Directory traversal

"Sametime Android potential path traversal vulnerability when using File class"

CVE-2021-27755 5.5 - Medium - February 21, 2022

"Sametime Android potential path traversal vulnerability when using File class"

Directory traversal

"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability

CVE-2020-14264 3.9 - Low - October 25, 2021

"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"

Use of a Broken or Risky Cryptographic Algorithm

"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability

CVE-2020-14263 3.9 - Low - October 21, 2021

"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"

Incorrect Permission Assignment for Critical Resource

In Digital Experience 8.5

CVE-2020-4081 6.1 - Medium - February 02, 2021

In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).

XSS

HCL Digital Experience 8.5

CVE-2020-14221 4.9 - Medium - February 02, 2021

HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.

Information Disclosure

HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests

CVE-2020-14255 7.5 - High - February 02, 2021

HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditional on-premise installations.

Information Disclosure

HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API

CVE-2020-14273 7.5 - High - December 28, 2020

HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino server.

Improper Input Validation

HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input

CVE-2020-14270 5.3 - Medium - December 22, 2020

HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthenticated attacker could exploit this vulnerability to obtain information about the XPages software running on the Domino server.

Generation of Error Message Containing Sensitive Information

HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content

CVE-2020-14225 6.5 - Medium - December 21, 2020

HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack.

HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content

CVE-2020-14271 6.1 - Medium - December 18, 2020

HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

XSS

A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow

CVE-2020-14224 9.8 - Critical - December 18, 2020

A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the Notes application or inject code into the system which would execute with the privileges of the currently logged-in user.

Memory Corruption

HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content

CVE-2020-4080 6.1 - Medium - December 18, 2020

HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

XSS

A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow

CVE-2020-14232 8.8 - High - December 18, 2020

A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the privileges of the currently logged in user.

BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session

CVE-2020-14248 5.3 - Medium - December 16, 2020

BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

Cleartext Transmission of Sensitive Information

TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2

CVE-2020-14254 7.5 - High - December 16, 2020

TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.

Missing Encryption of Sensitive Data

A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow

CVE-2020-14244 9.8 - Critical - December 14, 2020

A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which would execute with the privileges of the server.

Memory Corruption

A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow

CVE-2020-14268 9.8 - Critical - December 14, 2020

A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which would execute with the privileges of the client.

Memory Corruption

HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input

CVE-2020-14260 9.8 - Critical - December 02, 2020

HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Domino or execute attacker-controlled code on the server system.

Classic Buffer Overflow

HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input

CVE-2020-4102 6.7 - Medium - December 02, 2020

HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Notes or execute attacker-controlled code on the client system.

Classic Buffer Overflow

HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service

CVE-2020-4128 5.3 - Medium - December 01, 2020

HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the ID Vault service.

authentification

HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service

CVE-2020-4129 5.3 - Medium - December 01, 2020

HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the LDAP service. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and 11.0.1 FP1 and later.

HCL iNotes is susceptible to a sensitive cookie exposure vulnerability

CVE-2020-4126 5.9 - Medium - December 01, 2020

HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later.

Information Disclosure

HCL Domino is susceptible to a Login CSRF vulnerability

CVE-2020-4127 6.5 - Medium - November 30, 2020

HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and 11.0.1 FP1 and later.

Session Riding

HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input

CVE-2020-14234 7.5 - High - November 21, 2020

HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the ability to crash the server. Versions previous to release 9.0.1 FP10 IF6 and release 10.0.1 are affected.

Improper Input Validation

HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input

CVE-2020-14230 7.5 - High - November 21, 2020

HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the server. Versions previous to releases 9.0.1 FP10 IF6, 10.0.1 FP5 and 11.0.1 are affected.

Improper Input Validation

HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input

CVE-2020-14258 7.5 - High - November 21, 2020

HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the client. Versions 9, 10 and 11 are affected.

Improper Input Validation

HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS)

CVE-2020-14222 6.1 - Medium - November 05, 2020

HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).

XSS

In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8

CVE-2020-4097 6.8 - Medium - November 05, 2020

In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an attacker resulting in a buffer overflow. This could enable an attacker to crash HCL Notes or execute attacker-controlled code on the client.

Classic Buffer Overflow

HCL Notes versions previous to releases 9.0.1 FP10 IF8

CVE-2020-14240 6.1 - Medium - November 05, 2020

HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

XSS

HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS)

CVE-2020-14223 6.1 - Medium - October 01, 2020

HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.

XSS

"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could

CVE-2019-4323 4.3 - Medium - July 07, 2020

"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."

Clickjacking

"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy

CVE-2019-4324 6.1 - Medium - July 07, 2020

"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."

XSS

"If port encryption is not enabled on the Domino Server

CVE-2020-4092 5.3 - Medium - May 06, 2020

"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can potentially expose sensitive information including but not limited to server names, user IDs and document content."

Cleartext Transmission of Sensitive Information

HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability

CVE-2019-4209 6.1 - Medium - May 01, 2020

HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.

Open Redirect

"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user

CVE-2020-4085 6.5 - Medium - April 22, 2020

"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."

Information Disclosure

"HCL AppScan Enterprise uses hard-coded credentials

CVE-2019-4327 7.5 - High - April 21, 2020

"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."

Use of Hard-coded Credentials

HCL AppScan Standard is vulnerable to excessive authorization attempts

CVE-2019-4393 9.8 - Critical - April 07, 2020

HCL AppScan Standard is vulnerable to excessive authorization attempts

Improper Restriction of Excessive Authentication Attempts

HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data

CVE-2019-4391 8.2 - High - April 07, 2020

HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data

XXE

HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting

CVE-2020-4084 5.4 - Medium - March 09, 2020

HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

XSS

HCL Connections 6.5 is vulnerable to possible information leakage

CVE-2020-4083 5.5 - Medium - March 05, 2020

HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.

Insertion of Sensitive Information into Log File

The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input

CVE-2020-4082 5.4 - Medium - March 05, 2020

The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

XSS

BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Running Message or Post Message HTML.

CVE-2019-4301 8.4 - High - February 28, 2020

BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Running Message or Post Message HTML.

HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials

CVE-2019-4392 9.8 - Critical - February 14, 2020

HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.

Use of Hard-coded Credentials

HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by

CVE-2019-4388 4.8 - Medium - December 18, 2019

HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.

XSS

HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks

CVE-2019-4409 5.4 - Medium - October 18, 2019

HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message that includes the entered file name. If the file name is not escaped in the returned error page, it could expose a cross-site scripting (XSS) vulnerability.

XSS

HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations

CVE-2019-16188 7.1 - High - September 25, 2019

HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to open it. When the victim imports the .ozasmt file in AppScan Source, the content of any file in the local file system (to which the victim as read access) can be exfiltrated to a remote listener under the attacker's control. The product does not disable external XML Entity Processing, which can lead to information disclosure and denial of services attacks.

XXE

Built by Foundeo Inc., with data from the National Vulnerability Database (NVD), Icons by Icons8. Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.