Vulnerabilities
Vulnerable Software
Hcltech:  Security Vulnerabilities
An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.
CVSS Score
3.5
EPSS Score
0.004
Published
2024-03-28
An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.
CVSS Score
2.0
EPSS Score
0.003
Published
2024-03-28
The console may experience a service interruption when processing file names with invalid characters.
CVSS Score
3.5
EPSS Score
0.004
Published
2024-03-28
Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the hashed value to determine a user's password, e.g. using a brute force attack. This issue does not impact Person documents created through user registration https://help.hcltechsw.com/domino/10.0.1/admin/conf_userregistration_c.html .
CVSS Score
5.9
EPSS Score
0.005
Published
2024-02-29
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerability as identified in CVE-2023-37530.
CVSS Score
3.0
EPSS Score
0.003
Published
2024-02-29
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information.
CVSS Score
3.0
EPSS Score
0.003
Published
2024-02-29
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.
CVSS Score
3.3
EPSS Score
0.004
Published
2024-02-29
Sametime Connect desktop chat client includes, but does not use or require, the use of an Eclipse feature called Secure Storage. Using this Eclipse feature to store sensitive data can lead to exposure of that data.
CVSS Score
3.9
EPSS Score
0.002
Published
2024-02-23
HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.
CVSS Score
5.5
EPSS Score
0.003
Published
2024-02-12
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
CVSS Score
4.8
EPSS Score
0.003
Published
2024-02-10


Contact Us

Shodan ® - All rights reserved