Vulnerabilities
Vulnerable Software
Hcltech:  Security Vulnerabilities
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform.  An attacker could hijack a user's session and perform other attacks.
CVSS Score
8.1
EPSS Score
0.005
Published
2023-08-03
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform.  An attacker could hijack a user's session and perform other attacks.
CVSS Score
8.1
EPSS Score
0.005
Published
2023-08-03
HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
CVSS Score
8.3
EPSS Score
0.002
Published
2023-08-01
HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.
CVSS Score
5.4
EPSS Score
0.005
Published
2023-07-27
HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.
CVSS Score
6.6
EPSS Score
0.001
Published
2023-07-27
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-07-26
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 
CVSS Score
4.9
EPSS Score
0.001
Published
2023-07-18
 URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
CVSS Score
4.7
EPSS Score
0.002
Published
2023-07-18
The BigFix WebUI uses weak cipher suites.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-07-18
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.
CVSS Score
5.5
EPSS Score
0.001
Published
2023-07-18


Contact Us

Shodan ® - All rights reserved