Vulnerabilities
Vulnerable Software
Hcltech:  Security Vulnerabilities
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information.
CVSS Score
3.0
EPSS Score
0.008
Published
2024-02-29
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.
CVSS Score
3.3
EPSS Score
0.005
Published
2024-02-29
HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.
CVSS Score
5.5
EPSS Score
0.0
Published
2024-02-12
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
CVSS Score
4.8
EPSS Score
0.001
Published
2024-02-10
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.
CVSS Score
4.0
EPSS Score
0.002
Published
2024-02-10
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  
CVSS Score
3.9
EPSS Score
0.002
Published
2024-02-09
Sametime is impacted by sensitive information passed in URL.
CVSS Score
1.7
EPSS Score
0.001
Published
2024-02-09
Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the application.
CVSS Score
5.9
EPSS Score
0.001
Published
2024-02-09
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.
CVSS Score
6.5
EPSS Score
0.003
Published
2024-02-03
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
CVSS Score
3.0
EPSS Score
0.003
Published
2024-02-02


Contact Us

Shodan ® - All rights reserved