Vulnerabilities
Vulnerable Software
Security Vulnerabilities
HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.
CVSS Score
2.6
EPSS Score
0.001
Published
2026-07-21
HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.
CVSS Score
3.1
EPSS Score
0.001
Published
2026-07-21
HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.
CVSS Score
2.2
EPSS Score
0.002
Published
2026-07-21
HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.
CVSS Score
3.1
EPSS Score
0.002
Published
2026-07-21
A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.
CVSS Score
6.0
EPSS Score
0.002
Published
2026-07-21
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.
CVSS Score
7.3
EPSS Score
0.002
Published
2026-07-21
A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.
CVSS Score
6.9
EPSS Score
0.002
Published
2026-07-21
A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.
CVSS Score
1.8
EPSS Score
0.001
Published
2026-07-21
HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.
CVSS Score
3.1
EPSS Score
0.001
Published
2026-07-21
HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.
CVSS Score
3.1
EPSS Score
0.001
Published
2026-07-21


Contact Us

Shodan ® - All rights reserved