HCLSoftware Vulnerabilities and Affected Products
Vulnerabilities associated with IntelliOps Event Management.
Products
Clear product- Aftermarket EPC14 vulnerabilities
- MyCloud7 vulnerabilities
- Connections6 vulnerabilities
- DevOps Loop4 vulnerabilities
- IntelliOps Event Management4 vulnerabilities
- BigFix IVR3 vulnerabilities
- HCL DevOps Deploy / HCL Launch3 vulnerabilities
- Traveler for Microsoft Outlook3 vulnerabilities
- BigFix Platform2 vulnerabilities
- BigFix Service Management (SM)2 vulnerabilities
- BigFix WebUI2 vulnerabilities
- DevOps Plan2 vulnerabilities
- DFXServer2 vulnerabilities
- Digital Experience2 vulnerabilities
- HCL BigFix Mobile2 vulnerabilities
- Traveler2 vulnerabilities
- BigFix Cloud Lifecycle Management1 vulnerability
- BigFix Compliance1 vulnerability
- BigFix Remote Control Server1 vulnerability
- BigFix SCM Reporting1 vulnerability
- Commerce1 vulnerability
- DevOps Deploy1 vulnerability
- DFMPro for CATIA1 vulnerability
- DFXAnalytics1 vulnerability
- Digital Experience & DX Compose1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
HCL IEM was affected with X-Content-Type-Options Header MissingHCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data. CWE-16Jul 21, 2026 | CVSS3.1v3.1 | EPSS0.122% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
HCL IEM was affected with the Anti Clickjacking XFrame Options Header MissingHCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions. CWE-693Jul 21, 2026 | CVSS3.1v3.1 | EPSS0.145% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
HCL IEM was affected with Strict transport security not enforcedHCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications. CWE-523Jul 21, 2026 | CVSS3.7v3.1 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
HCL IEM was affected with the Information disclosure nginx serverHCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits. CWE-200Jul 21, 2026 | CVSS3.7v3.1 | EPSS0.172% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |