Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Total 455 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-52612 1 Hcltech 1 Icontrol 2026-07-22 N/A 7.1 HIGH
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .
CVE-2025-52608 1 Hcltech 1 Icontrol 2026-07-22 N/A 3.1 LOW
HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.
CVE-2025-52606 1 Hcltech 1 Icontrol 2026-07-22 N/A 4.3 MEDIUM
HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
CVE-2025-52609 1 Hcltech 1 Icontrol 2026-07-22 N/A 3.7 LOW
HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers.
CVE-2026-35149 1 Hcltech 1 Dfx Server 2026-07-21 N/A 8.2 HIGH
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.
CVE-2026-35148 1 Hcltech 1 Dfx Server 2026-07-21 N/A 6.3 MEDIUM
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.
CVE-2026-35147 1 Hcltech 1 Dfx Server 2026-07-21 N/A 8.2 HIGH
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials.
CVE-2026-35146 1 Hcltech 1 Dfx Server 2026-07-21 N/A 6.3 MEDIUM
HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.
CVE-2026-56456 1 Hcltech 1 Dfxanalytics 2026-07-17 N/A 5.3 MEDIUM
HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which could allow a remote attacker to map the underlying server environment and identify targets for further exploitation.
CVE-2026-56455 1 Hcltech 1 Dfxanalytics 2026-07-17 N/A 5.3 MEDIUM
HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system to crash or become unresponsive. To mitigate this flaw, comprehensive input length checks must be implemented and enforced on both the client and server sides.
CVE-2026-56454 1 Hcltech 1 Dfxanalytics 2026-07-17 N/A 5.9 MEDIUM
HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and exclusively enable support for secure protocols, specifically TLS 1.2 and TLS 1.3.
CVE-2026-56453 1 Hcltech 1 Dfxanalytics 2026-07-17 N/A 5.5 MEDIUM
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts.
CVE-2026-35145 1 Hcltech 1 Dfxanalytics 2026-07-17 N/A 3.1 LOW
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.
CVE-2026-35140 1 Hcltech 1 Dfxanalytics 2026-07-17 N/A 3.0 LOW
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.
CVE-2026-35141 1 Hcltech 1 Dfxanalytics 2026-07-17 N/A 2.6 LOW
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejected by the recipient system.
CVE-2026-35142 1 Hcltech 1 Dfxanalytics 2026-07-17 N/A 2.6 LOW
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.
CVE-2026-35143 1 Hcltech 1 Dfxanalytics 2026-07-17 N/A 3.0 LOW
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF tokens, are not implemented.
CVE-2025-31991 1 Hcltech 1 Devops Velocity 2026-07-07 N/A 6.8 MEDIUM
Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.
CVE-2024-23581 1 Hcltech 1 Traveler For Microsoft Outlook 2026-07-06 N/A 6.7 MEDIUM
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.
CVE-2023-37524 1 Hcltech 1 Traveler For Microsoft Outlook 2026-07-06 N/A 7.7 HIGH
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service.  Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party components.