Skip to main content

Vendor archive

hcltech CVEs

Beta · best-effort

439 CVEs tagged to vendor hcltech18 Critical, 74 High, 212 Medium, 135 Low, 0 Unrated.

CVE-2019-4209

Published May 1, 2020

HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4085

Published Apr 22, 2020

"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4327

Published Apr 21, 2020

"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4393

Published Apr 7, 2020

HCL AppScan Standard is vulnerable to excessive authorization attempts

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-4391

Published Apr 7, 2020

HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4084

Published Mar 9, 2020

HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the int…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4083

Published Mar 5, 2020

HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4082

Published Mar 5, 2020

The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4301

Published Feb 28, 2020

BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Running Message or Post Message HTML.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4392

Published Feb 14, 2020

HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-4388

Published Dec 18, 2019

HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4409

Published Oct 18, 2019

HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16188

Published Sep 25, 2019

HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11518

Published May 30, 2018

A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio signals; based on the frequency, c…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 426-439 of 439 CVEsPage 18 of 18