In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticat…
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticate…
HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthentica…
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in u…
In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.
In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.
Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Dire…
HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directo…
HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnera…
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An atta…
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools t…
User input included in error response, which could be used in a phishing attack.
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
HCL VersionVault Express exposes administrator credentials.
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which…
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sen…
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with …
BigFix Web Reports authorized users may see SMTP credentials in clear text.
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that…
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this …
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validatio…
The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We ass…
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal m…
Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conv…
Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was ab…