Vulnerabilities
Vulnerable Software
Hcltechsw:  Security Vulnerabilities
HCL Workload Automation could allow a local user to overwrite key system files which would cause the system to crash.
CVSS Score
6.2
EPSS Score
0.0
Published
2022-12-12
HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.
CVSS Score
4.9
EPSS Score
0.001
Published
2022-12-12
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
CVSS Score
5.3
EPSS Score
0.002
Published
2022-08-03
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.
CVSS Score
3.9
EPSS Score
0.001
Published
2022-07-30
HCL Launch stores user credentials in plain clear text which can be read by a local user.
CVSS Score
4.9
EPSS Score
0.001
Published
2022-07-06
HCL Launch may store certain data for recurring activities in a plain text format.
CVSS Score
4.0
EPSS Score
0.0
Published
2022-07-06
HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.
CVSS Score
4.4
EPSS Score
0.0
Published
2022-05-06
"HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability"
CVSS Score
5.4
EPSS Score
0.003
Published
2021-10-21
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
CVSS Score
9.1
EPSS Score
0.004
Published
2021-08-13
HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources.
CVSS Score
9.8
EPSS Score
0.004
Published
2021-02-04


Contact Us

Shodan ® - All rights reserved