Vulnerabilities
Vulnerable Software
Hcltech:  Security Vulnerabilities
An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.
CVSS Score
7.8
EPSS Score
0.002
Published
2023-10-17
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
CVSS Score
9.3
EPSS Score
0.004
Published
2023-10-11
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
CVSS Score
8.2
EPSS Score
0.014
Published
2023-10-11
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.
CVSS Score
6.5
EPSS Score
0.003
Published
2023-10-11
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.
CVSS Score
6.5
EPSS Score
0.003
Published
2023-10-11
Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.
CVSS Score
4.6
EPSS Score
0.002
Published
2023-10-11
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.
CVSS Score
4.0
EPSS Score
0.003
Published
2023-09-08
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
CVSS Score
3.3
EPSS Score
0.002
Published
2023-08-11
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
CVSS Score
3.3
EPSS Score
0.002
Published
2023-08-11
If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved.
CVSS Score
3.5
EPSS Score
0.003
Published
2023-08-11


Contact Us

Shodan ® - All rights reserved