Hcltech
185 known vulnerabilities
Top Products
HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using
HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular acce
HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions
HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Va
HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config
HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It inv
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosi
HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they ar
HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session h
HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sen
HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session
HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit
HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed infor
HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities
HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force o
HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man
HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the appli
HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or ma
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon
HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this v
HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restric
HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections ag
HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may
HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper a
HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently
HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The applicat
HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite"
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP ad
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to interce
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The applicat
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized us
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints ar
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verif
HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish conn
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of servi
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, t
IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by th
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An att
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker ca
HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script
HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to
Frequently Asked Questions
How many CVEs affect Hcltech?
Hcltech has 185 CVE records in our database, including 2 critical and 14 high severity vulnerabilities.
What are the most severe Hcltech vulnerabilities?
Hcltech has 2 critical severity (CVSS 9.0+) and 14 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Hcltech vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Hcltech products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Hcltech Vulnerabilities
CyberStrike scans your infrastructure for Hcltech vulnerabilities and provides real-time remediation guidance.
Get Started