Vulnerabilidades em HCL

89 resultados
Análise Vexday

O portfólio de vulnerabilidades da HCL reúne 88 CVEs catalogadas, com volume recente relevante — 32 entradas nos últimos 90 dias —, sinalizando atividade contínua de descoberta e divulgação. Apesar disso, o risco operacional imediato é baixo: nenhuma CVE consta no catálogo KEV da CISA, taxa inferior à média geral do catálogo, e nenhuma prova de conceito pública foi identificada. A falha mais frequente é CWE-200 (exposição indevida de informações), padrão que costuma favorecer reconhecimento e coleta de dados sensíveis quando combinado a outras fraquezas. A CVE mais perigosa atualmente monitorada, CVE-2020-14258, apresenta EPSS de 0,0125, indicando probabilidade de exploração ativa baixa, mas sua antiguidade reforça a importância de verificar se os ativos afetados receberam as correções devidas.

CVE-2025-52635LOWHCL AION is susceptible to Trusted types in scripts not enforced in CSPEPSS 0.2%CVE-2025-31951HIGHHCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerabilityEPSS 0.2%CVE-2025-55269MEDIUMHCL Aftermarket DPC is affected by Weak Password Policy vulnerabilityEPSS 0.2%CVE-2025-52653HIGHCross Site Scripting vulnerability in the web applicationEPSS 0.2%CVE-2025-31960MEDIUMHCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting moduleEPSS 0.2%CVE-2025-52656HIGHHCL MyXalytics product is affected by Mass Assignment vulnerabilityEPSS 0.2%CVE-2025-52613MEDIUMHCL BigFix Service Management (SM) is affected by use of a vulnerable componentEPSS 0.2%CVE-2025-55273MEDIUMHCL Aftermarket DPC is affected by Cross Domain Script Include vulnerabilityEPSS 0.2%CVE-2025-52637MEDIUMMultiple security vulnerabilities affect HCL AIONEPSS 0.2%CVE-2025-55272LOWHCL Aftermarket DPC is affected by Banner Disclosure vulnerabilityEPSS 0.2%CVE-2025-52634LOWHCL AION is susceptible to Spring Boot Actuator Endpoints ExposedEPSS 0.2%CVE-2025-52625LOWHCL AION is susceptible to Cacheable SSL Page Found vulnerabilityEPSS 0.2%CVE-2025-52630LOWHCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerabilityEPSS 0.2%CVE-2025-52650HIGHHCL AION is susceptible to Inline script execution allowed in CSP vulnerabilityEPSS 0.2%CVE-2025-62345LOWHCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” VulnerabilityEPSS 0.2%CVE-2025-55275LOWHCL Aftermarket DPC is affected by Admin Session Concurrency vulnerabilityEPSS 0.2%CVE-2025-59851LOWHCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerabilityEPSS 0.2%CVE-2025-55276LOWHCL Aftermarket DPC is affected by Internal IP Disclosure vulnerabilityEPSS 0.2%CVE-2025-52631LOWHCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability.EPSS 0.2%CVE-2025-52612HIGHHCL iControl was affected by Export CSV - CSV Injection vulnerability.EPSS 0.2%