Hcltech
190 known vulnerabilities
Top Products
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before s
HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, th
Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Bool
HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers
HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu
HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient aut
HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of
HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isola
HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or
HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of
HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in applica
HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application
IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the
IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to bru
HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which wo
HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow
HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensiti
HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to
HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow au
HCL AION is susceptible to Missing Content-Security-Policy. An The absence of a CSP header may increase the risk of cr
Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critic
A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially
A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF d
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable pas
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical detail
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may
HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse,
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re
HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensit
HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secr
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authentic
HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particul
A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on vari
Frequently Asked Questions
How many CVEs affect Hcltech?
Hcltech has 190 CVE records in our database, including 2 critical and 17 high severity vulnerabilities.
What are the most severe Hcltech vulnerabilities?
Hcltech has 2 critical severity (CVSS 9.0+) and 17 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Hcltech vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Hcltech products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Hcltech Vulnerabilities
CyberStrike scans your infrastructure for Hcltech vulnerabilities and provides real-time remediation guidance.
Get Started