Vulnerabilities
Vulnerable Software
Hcltechsw:  Security Vulnerabilities
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker to execute a malicious attack.
CVSS Score
2.3
EPSS Score
0.002
Published
2024-01-16
An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts..
CVSS Score
6.2
EPSS Score
0.0
Published
2023-12-28
HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
CVSS Score
4.3
EPSS Score
0.001
Published
2023-12-28
HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
CVSS Score
4.3
EPSS Score
0.001
Published
2023-12-21
HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion.
CVSS Score
5.3
EPSS Score
0.001
Published
2023-12-21
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.
CVSS Score
5.1
EPSS Score
0.001
Published
2023-07-10
HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
CVSS Score
4.6
EPSS Score
0.004
Published
2023-04-02
Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure.  This requires privileged network access.
CVSS Score
6.4
EPSS Score
0.001
Published
2022-12-21
Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires privileged access. 
CVSS Score
6.4
EPSS Score
0.003
Published
2022-12-21
HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.
CVSS Score
8.6
EPSS Score
0.007
Published
2022-12-12


Contact Us

Shodan ® - All rights reserved