Vulnerabilidades em HCL Software

334 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2024-42192MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakageEPSS 0.1%CVE-2025-31959LOWHCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images.EPSS 0.1%CVE-2023-28023MEDIUMHCL BigFix WebUI Software Distribution is affected by a cross site server request forgery vulnerabilityEPSS 0.1%CVE-2025-0252LOWHCL IEM is affected by a password in cleartext vulnerabilityEPSS 0.1%CVE-2024-42184LOWHCL BigFix Patch Download Plug-ins are affected by insecure support for file URI schemeEPSS 0.1%CVE-2024-23589MEDIUMHCL Glovius Cloud is susceptible to an Outdated Hash Algorithm vulnerabilityEPSS 0.1%CVE-2025-31961LOWHCL Connections is vulnerable to broken access controlEPSS 0.1%CVE-2025-52602MEDIUMHCL BigFix Query is affected by a sensitive information disclosure vulnerability in the WebUI Query applicationEPSS 0.1%CVE-2024-30154MEDIUMHCL SX is susceptible to a Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.1%CVE-2025-31978MEDIUMHCL BigFix Service Management (SM) does not adequately sanitize or safely renderEPSS 0.1%CVE-2024-30125MEDIUMHCL BigFix Compliance is affected by an internal server errorEPSS 0.1%CVE-2025-62330MEDIUMHCL DevOps Deploy is susceptible to a cleartext transmission of sensitive informationEPSS 0.1%CVE-2024-42177LOWHCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilitiesEPSS 0.1%CVE-2025-55250LOWHCL AION is affected by a Technical Error Disclosure vulnerabilityEPSS 0.1%CVE-2023-37516LOWHCL Leap is affected by missing "no cache" headersEPSS 0.1%CVE-2025-31971MEDIUMAIML Solutions for HCL SX is susceptible to a URL validation vulnerabilityEPSS 0.1%CVE-2024-30127LOWHCL Leap is affected by missing "no cache" headersEPSS 0.1%CVE-2022-38659MEDIUMHCL BigFix Platform is affected by insecure credential storageEPSS 0.1%CVE-2025-52614LOWHCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerabilityEPSS 0.1%CVE-2023-45716LOWHCL Sametime is impacted by a sensitive information disclosureEPSS 0.1%