Hcltech
190 known vulnerabilities
Top Products
HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by
HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing s
HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an ar
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outd
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to vie
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privile
HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configur
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its repor
HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty
HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This cou
HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed direct
HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) befo
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while comm
HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Expose
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to co
HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead t
HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes t
HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack tr
HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted ove
HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatc
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Polic
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, al
HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise wh
HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem str
Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brut
HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive a
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys l
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a s
HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or i
HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensiti
HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his pri
HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make us
HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organiz
HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurren
HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the expo
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts ca
HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s softw
HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application h
HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can
HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak
HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume se
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicio
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carr
HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files
HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provid
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbi
A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cros
Frequently Asked Questions
How many CVEs affect Hcltech?
Hcltech has 190 CVE records in our database, including 2 critical and 17 high severity vulnerabilities.
What are the most severe Hcltech vulnerabilities?
Hcltech has 2 critical severity (CVSS 9.0+) and 17 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Hcltech vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Hcltech products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Hcltech Vulnerabilities
CyberStrike scans your infrastructure for Hcltech vulnerabilities and provides real-time remediation guidance.
Get Started