Vulnerabilities
Vulnerable Software
Hcltech:  Security Vulnerabilities
HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.
CVSS Score
3.7
EPSS Score
0.002
Published
2026-08-03
HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.
CVSS Score
4.8
EPSS Score
0.001
Published
2026-08-03
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
CVSS Score
5.1
EPSS Score
0.001
Published
2026-07-31
HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status
CVSS Score
3.7
EPSS Score
0.002
Published
2026-07-31
HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
CVSS Score
4.0
EPSS Score
0.001
Published
2026-07-31
HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions.
CVSS Score
3.7
EPSS Score
0.002
Published
2026-07-31
HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated.
CVSS Score
3.7
EPSS Score
0.002
Published
2026-07-31
HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.
CVSS Score
3.5
EPSS Score
0.002
Published
2026-07-27
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.
CVSS Score
3.5
EPSS Score
0.002
Published
2026-07-27
HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.
CVSS Score
2.6
EPSS Score
0.002
Published
2026-07-21


Contact Us

Shodan ® - All rights reserved