hcltech

395 tracked vulnerabilities.

CVE-2021-27767 MEDIUM
BigFix Console - Privilege Escalation
May 06, 2022
CVSS 6.7
EPSS 0.00
CVE-2021-27766 MEDIUM
BigFix Client - Privilege Escalation
May 06, 2022
CVSS 6.7
EPSS 0.00
CVE-2021-27765 MEDIUM
BigFix Server API - Privilege Escalation
May 06, 2022
CVSS 6.7
EPSS 0.00
CVE-2021-27764 HIGH
HCL BigFix WebUI - Insecure Cookie Permission Assignment
May 06, 2022
CVSS 7.4
EPSS 0.00
CVE-2021-27762 MEDIUM
Misconfigured Security Headers - Info Disclosure
May 06, 2022
CVSS 4.7
EPSS 0.00
CVE-2021-27761 MEDIUM
Web Transport Security - Info Disclosure
May 06, 2022
CVSS 4.8
EPSS 0.00
CVE-2021-27760 MEDIUM
Notes 11.0-11.0.1 FP4 - Authenticated RCE
May 06, 2022
CVSS 4.6
EPSS 0.00
CVE-2021-27759 LOW
HCLTech BigFix Inventory 9.0 through 10.0.7.0 - Cross-Site Request Forgery
May 06, 2022
CVSS 2.3
EPSS 0.00
CVE-2021-27758 MEDIUM
Login Form - Cross-Site Request Forgery
May 06, 2022
CVSS 4.3
EPSS 0.00
CVE-2021-27756 HIGH
BigFix Compliance <v2.0.5 - Info Disclosure
Mar 04, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-27757 HIGH
Insecure Password Storage - Info Disclosure
Mar 04, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-27755 MEDIUM
HCL Sametime < 11.6.5 - Path Traversal via File Class
Feb 21, 2022
CVSS 5.5
EPSS 0.00
CVE-2021-27753 MEDIUM
HCL Sametime < 11.6.5 - Path Traversal
Feb 21, 2022
CVSS 5.5
EPSS 0.00
CVE-2020-4099 MEDIUM
HCL Verse < 12.0.15 - Inadequate Encryption Strength via Weak Key Length
Nov 01, 2022
CVSS 5.9
EPSS 0.00
CVE-2020-4107 HIGH
HCL Domino - Authenticated Insufficient Access Control
May 19, 2022
CVSS 8.8
EPSS 0.00
CVE-2020-14264 LOW
HCL Traveler Companion < 12.0.0 - Weak Cryptographic Process via MobileIron AppConnect SDK
Oct 25, 2021
CVSS 3.9
EPSS 0.00
CVE-2020-14263 LOW
HCL Traveler Companion < 12.0.0 - Weak Cryptographic Process via MobileIron AppConnect SDK
Oct 21, 2021
CVSS 3.9
EPSS 0.00
CVE-2020-4081 MEDIUM
HCL Digital Experience 8.5, 9.0, 9.5 - Cross-Site Scripting in WSRP Consumer
Feb 02, 2021
CVSS 6.1
EPSS 0.00
CVE-2020-14255 HIGH
HCL Digital Experience <9.5 - Info Disclosure
Feb 02, 2021
CVSS 7.5
EPSS 0.00
CVE-2020-14221 MEDIUM
HCL Digital Experience <9.5 - Info Disclosure
Feb 02, 2021
CVSS 4.9
EPSS 0.00
CVE-2020-14273 HIGH
HCL Domino - Unauthenticated Denial of Service via Public API Input
Dec 28, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-14270 MEDIUM
HCL Domino 9.0.0-10.0.0 - Unauthenticated Information Disclosure via XPages Error Handling
Dec 22, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-14225 MEDIUM
HCL iNotes - Tabnabbing via Improper Message Content Sanitization
Dec 21, 2020
CVSS 6.5
EPSS 0.01
CVE-2020-14271 MEDIUM
HCL iNotes 9.0-10.0.1 - Unauthenticated Stored Cross-Site Scripting via Message Content
Dec 18, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-14224 CRITICAL
HCL Notes v9 - Unauthenticated Stack Buffer Overflow in MIME Message Handling
Dec 18, 2020
CVSS 9.8
EPSS 0.02