Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Total 455 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-31969 1 Hcltech 1 Unica 2026-06-17 N/A 4.0 MEDIUM
HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.
CVE-2025-31966 1 Hcltech 1 Sametime 2026-06-17 N/A 2.7 LOW
HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.
CVE-2025-31964 1 Hcltech 1 Bigfix Insights For Vulnerability Remediation 2026-06-17 N/A 2.2 LOW
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
CVE-2025-31963 1 Hcltech 1 Bigfix Insights For Vulnerability Remediation 2026-06-17 N/A 2.9 LOW
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.
CVE-2025-31962 1 Hcltech 1 Bigfix Insights For Vulnerability Remediation 2026-06-17 N/A 2.0 LOW
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.
CVE-2025-31961 1 Hcltech 1 Connections 2026-06-17 N/A 3.7 LOW
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
CVE-2025-31960 1 Hcltech 1 Bigfix Service Management 2026-06-17 N/A 5.3 MEDIUM
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an unhandled exception.
CVE-2025-31959 1 Hcltech 1 Bigfix Service Management 2026-06-17 N/A 3.5 LOW
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
CVE-2025-31958 1 Hcltech 1 Bigfix Service Management 2026-06-17 N/A 3.7 LOW
HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking.
CVE-2025-31957 1 Hcltech 1 Bigfix Service Management 2026-06-17 N/A 2.6 LOW
HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data.
CVE-2025-31955 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 7.6 HIGH
HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system.
CVE-2025-31954 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 5.4 MEDIUM
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.
CVE-2025-31953 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 7.1 HIGH
HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.
CVE-2025-31952 1 Hcltech 1 Dryice Iautomate 2026-06-17 N/A 7.1 HIGH
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.
CVE-2025-0279 1 Hcltech 1 Traveler 2026-06-17 N/A 4.3 MEDIUM
HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks.
CVE-2025-0278 1 Hcltech 1 Traveler 2026-06-17 N/A 4.3 MEDIUM
HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests.
CVE-2025-0277 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2026-06-17 N/A 6.5 MEDIUM
HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
CVE-2025-0276 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2026-06-17 N/A 6.5 MEDIUM
HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
CVE-2025-0275 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2026-06-17 N/A 5.3 MEDIUM
HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
CVE-2025-0274 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2026-06-17 N/A 5.3 MEDIUM
HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.