Vulnerabilities (CVE)

Filtered by vendor Hcltech
Angry Yack Logo
Total 338 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-31997 1 Hcltech 1 Unica Centralized Offer Management 2025-10-29 N/A 4.2 MEDIUM
HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.
CVE-2025-31998 1 Hcltech 1 Unica Centralized Offer Management 2025-10-29 N/A 3.5 LOW
HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. An attacker can exploit use this information to exploit known vulnerabilities launch targeted attacks, such as remote code execution or denial of service.
CVE-2024-42209 1 Hcltech 1 Connections 2025-10-29 N/A 3.5 LOW
HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive information they are not entitled to, which is caused by improper handling of request data.
CVE-2024-42208 1 Hcltech 1 Connections 2025-10-29 N/A 3.5 LOW
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
CVE-2023-37541 1 Hcltech 1 Connections 2025-10-29 N/A 3.5 LOW
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
CVE-2024-23557 1 Hcltech 1 Connections 2025-10-29 N/A 3.5 LOW
HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack.
CVE-2024-30107 1 Hcltech 1 Connections 2025-10-29 N/A 3.5 LOW
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.
CVE-2024-30112 1 Hcltech 1 Connections 2025-10-28 N/A 5.4 MEDIUM
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise user's account then launch other attacks.
CVE-2024-42188 1 Hcltech 1 Connections 2025-10-28 N/A 3.7 LOW
HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.
CVE-2025-52630 1 Hcltech 1 Aion 2025-10-24 N/A 3.7 LOW
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.
CVE-2025-52632 1 Hcltech 1 Aion 2025-10-24 N/A 6.5 MEDIUM
A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.
CVE-2025-52634 1 Hcltech 1 Aion 2025-10-24 N/A 3.7 LOW
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.
CVE-2025-52650 1 Hcltech 1 Aion 2025-10-24 N/A 8.2 HIGH
Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0
CVE-2025-52624 1 Hcltech 1 Aion 2025-10-24 N/A 5.4 MEDIUM
A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects AION: 2.0.
CVE-2025-52625 1 Hcltech 1 Aion 2025-10-24 N/A 3.7 LOW
A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or browser This issue affects AION: 2.0.
CVE-2025-52635 1 Hcltech 1 Aion 2025-10-24 N/A 3.7 LOW
A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.
CVE-2025-0274 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2025-10-21 N/A 5.3 MEDIUM
HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
CVE-2025-0275 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2025-10-21 N/A 5.3 MEDIUM
HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
CVE-2025-0277 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2025-10-21 N/A 6.5 MEDIUM
HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
CVE-2025-52616 1 Hcltech 1 Unica 2025-10-21 N/A 5.3 MEDIUM
HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnerabilities in the application.
CVE-2025-31996 1 Hcltech 1 Unica 2025-10-21 N/A 5.3 MEDIUM
HCL Unica Platform is affected by unprotected files due to improper access controls.  These files may contain sensitive information such as private or system information that can be exploited by attackers to compromise the application, infrastructure, or users.
CVE-2025-0276 1 Hcltech 2 Bigfix Mobile, Bigfix Modern Client Management 2025-10-21 N/A 6.5 MEDIUM
HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
CVE-2025-52615 1 Hcltech 1 Unica 2025-10-20 N/A 3.5 LOW
HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treatment for the policies controlled by these headers.
CVE-2025-31969 1 Hcltech 1 Unica 2025-10-20 N/A 4.0 MEDIUM
HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.
CVE-2025-52614 1 Hcltech 1 Unica 2025-10-20 N/A 3.5 LOW
HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site.
CVE-2025-31961 1 Hcltech 1 Connections 2025-10-10 N/A 3.7 LOW
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
CVE-2025-0278 1 Hcltech 1 Traveler 2025-10-10 N/A 4.3 MEDIUM
HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests.
CVE-2025-0279 1 Hcltech 1 Traveler 2025-10-10 N/A 4.3 MEDIUM
HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks.
CVE-2025-31952 1 Hcltech 1 Dryice Iautomate 2025-10-10 N/A 7.1 HIGH
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.
CVE-2025-31953 1 Hcltech 1 Dryice Iautomate 2025-10-10 N/A 7.1 HIGH
HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.
CVE-2025-31955 1 Hcltech 1 Dryice Iautomate 2025-10-10 N/A 7.6 HIGH
HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system.
CVE-2024-42207 1 Hcltech 1 Dryice Iautomate 2025-10-10 N/A 5.5 MEDIUM
HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.
CVE-2025-52658 1 Hcltech 1 Dryice Myxalytics 2025-10-10 N/A 3.5 LOW
HCL MyXalytics is affected by the use of vulnerable/outdated versions which can expose the application to known security risks that could be exploited.
CVE-2025-52654 1 Hcltech 1 Dryice Myxalytics 2025-10-10 N/A 4.6 MEDIUM
HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing unauthorized content injection and manipulation.
CVE-2025-0251 1 Hcltech 1 Intelliops Event Management 2025-10-09 N/A 2.6 LOW
HCL IEM is affected by a concurrent login vulnerability.  The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks.
CVE-2025-0249 1 Hcltech 1 Intelliops Event Management 2025-10-09 N/A 3.3 LOW
HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.  A token was not invalidated which may allow attackers to access sensitive data without authorization.
CVE-2025-0250 1 Hcltech 1 Intelliops Event Management 2025-10-09 N/A 2.2 LOW
HCL IEM is affected by an authorization token sent in cookie vulnerability.  A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks.
CVE-2025-0252 1 Hcltech 1 Intelliops Event Management 2025-10-09 N/A 2.6 LOW
HCL IEM is affected by a password in cleartext vulnerability.  Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit.
CVE-2025-0253 1 Hcltech 1 Intelliops Event Management 2025-10-09 N/A 2.0 LOW
HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential vulnerabilities.
CVE-2024-42193 1 Hcltech 1 Bigfix Platform 2025-10-09 N/A 8.1 HIGH
HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.