Vulnerabilities
Vulnerable Software
Hcltech:  Security Vulnerabilities
In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.
CVSS Score
2.0
EPSS Score
0.002
Published
2022-12-19
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
CVSS Score
6.0
EPSS Score
0.0
Published
2022-12-19
 In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.
CVSS Score
6.1
EPSS Score
0.003
Published
2022-12-19
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.
CVSS Score
6.9
EPSS Score
0.0
Published
2022-12-19
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44754.  This vulnerability applies to software previously licensed by IBM.
CVSS Score
9.8
EPSS Score
0.024
Published
2022-12-19
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755.  This vulnerability applies to software previously licensed by IBM.
CVSS Score
9.8
EPSS Score
0.024
Published
2022-12-19
HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to software previously licensed by IBM.
CVSS Score
9.8
EPSS Score
0.012
Published
2022-12-19
Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users.
CVSS Score
6.5
EPSS Score
0.001
Published
2022-12-12
HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a user's person record.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-11-04
HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.  
CVSS Score
8.3
EPSS Score
0.001
Published
2022-11-04


Contact Us

Shodan ® - All rights reserved