Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Total 455 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-56584 1 Hcltech 1 Intelliops Event Management 2026-07-30 N/A 3.7 LOW
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.
CVE-2026-56587 1 Hcltech 1 Intelliops Event Management 2026-07-30 N/A 3.7 LOW
HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.
CVE-2026-56585 1 Hcltech 1 Intelliops Event Management 2026-07-30 N/A 3.1 LOW
HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.
CVE-2026-56586 1 Hcltech 1 Intelliops Event Management 2026-07-30 N/A 3.1 LOW
HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.
CVE-2023-37507 1 Hcltech 1 Devops Plan 2026-07-29 N/A 7.5 HIGH
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
CVE-2023-37508 1 Hcltech 1 Devops Plan 2026-07-29 N/A 6.1 MEDIUM
HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.
CVE-2025-36364 1 Hcltech 1 Devops Plan 2026-07-27 N/A 6.2 MEDIUM
IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.
CVE-2025-36363 1 Hcltech 1 Devops Plan 2026-07-27 N/A 5.9 MEDIUM
IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
CVE-2026-4096 1 Hcltech 1 Devops Plan 2026-07-27 N/A 6.5 MEDIUM
IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking
CVE-2024-22348 2 Hcltech, Ibm 2 Devops Velocity, Urbancode Velocity 2026-07-27 N/A 5.3 MEDIUM
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.
CVE-2024-22347 2 Hcltech, Ibm 2 Devops Velocity, Urbancode Velocity 2026-07-27 N/A 5.9 MEDIUM
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVE-2024-22349 2 Hcltech, Ibm 2 Devops Velocity, Urbancode Velocity 2026-07-27 N/A 4.0 MEDIUM
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.
CVE-2025-15633 1 Hcltech 21 Bigfix Webui Api, Bigfix Webui Application Administration, Bigfix Webui Cmep and 18 more 2026-07-25 N/A 6.5 MEDIUM
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.
CVE-2025-15634 1 Hcltech 21 Bigfix Webui Api, Bigfix Webui Application Administration, Bigfix Webui Cmep and 18 more 2026-07-25 N/A 4.3 MEDIUM
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.
CVE-2025-31985 1 Hcltech 1 Bigfix Service Management 2026-07-24 N/A 3.7 LOW
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly.
CVE-2025-31973 1 Hcltech 1 Bigfix Service Management 2026-07-24 N/A 4.0 MEDIUM
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.
CVE-2026-21825 1 Hcltech 2 Digital Experience, Digital Experience Compose 2026-07-23 N/A 6.1 MEDIUM
HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.
CVE-2026-21837 1 Hcltech 2 Digital Experience, Digital Experience Compose 2026-07-23 N/A 8.8 HIGH
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.
CVE-2026-21826 1 Hcltech 2 Digital Experience, Digital Experience Compose 2026-07-23 N/A 6.1 MEDIUM
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected ways.
CVE-2025-52611 1 Hcltech 1 Icontrol 2026-07-22 N/A 3.1 LOW
HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object that is undefined. This issue likely stems from one of the following: A missing or improperly initialized object.