Vulnerabilities
Vulnerable Software
Hcltech:  Security Vulnerabilities
HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entitled to due to the improper handling of request data.
CVSS Score
3.5
EPSS Score
0.001
Published
2024-10-28
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.
CVSS Score
3.6
EPSS Score
0.001
Published
2024-10-23
HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.
CVSS Score
5.8
EPSS Score
0.001
Published
2024-10-23
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.
CVSS Score
2.5
EPSS Score
0.001
Published
2024-10-14
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly handling the request data.
CVSS Score
3.5
EPSS Score
0.001
Published
2024-10-09
HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.
CVSS Score
5.3
EPSS Score
0.002
Published
2024-09-27
HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.
CVSS Score
4.7
EPSS Score
0.001
Published
2024-07-18
HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.
CVSS Score
6.2
EPSS Score
0.0
Published
2024-07-18
A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain information to launch further attacks against the affected system.
CVSS Score
5.3
EPSS Score
0.002
Published
2024-07-08
HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.
CVSS Score
5.3
EPSS Score
0.001
Published
2024-07-05


Contact Us

Shodan ® - All rights reserved