Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dryice Iautomate HIGH 7.1
CVE-2023-23347

HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and inte…

No fix yet
Fix from $1,950 2023-08-09
Dryice Mycloud HIGH 7.1
CVE-2023-23346

HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integr…

Mitigation only
Fix from $1,950 2023-08-09
Unica MEDIUM 6.1
CVE-2023-37501

A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign.  An attacker could hijack a user's session and perform other …

Fix: 12.1.1+
Fix from $1,600 2023-08-03
Unica HIGH 8.8
CVE-2023-37497

The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights …

Fix: 11.1.0.6 / 12.1.1+
Fix from $1,950 2023-08-03
Unica HIGH 8.8
CVE-2023-37498

A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator.  It is possible that an attacker…

Fix: 12.1.1+
Fix from $1,950 2023-08-03
Unica MEDIUM 6.1
CVE-2023-37499

A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform.  An attacker could hijack a user's…

Fix: 12.1.1+
Fix from $1,600 2023-08-03
Unica MEDIUM 6.1
CVE-2023-37500

A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform.  An attacker could hijack a user's sessi…

Fix: 12.1.1+
Fix from $1,600 2023-08-03
Verse MEDIUM 5.4
CVE-2023-37496

HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform…

Fix: 3.1+
Fix from $1,600 2023-08-01
Bigfix Mobile HIGH 8.8
CVE-2023-28012

HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.

Mitigation only
Fix from $1,950 2023-07-27
Bigfix Mobile MEDIUM 5.4
CVE-2023-28014

HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.

Mitigation only
Fix from $1,600 2023-07-27
Verse MEDIUM 6.1
CVE-2023-28013

HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthen…

Fix: 3.1+
Fix from $1,600 2023-07-26
Bigfix Webui MEDIUM 6.5
CVE-2023-28023

A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to a…

Fix: after 44
Fix from $1,600 2023-07-18
Bigfix Webui HIGH 7.5
CVE-2023-28021

The BigFix WebUI uses weak cipher suites.

No fix yet
Fix from $1,950 2023-07-18
Bigfix Webui MEDIUM 6.1
CVE-2023-28020

 URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response…

Mitigation only
Fix from $1,600 2023-07-18
Bigfix Webui HIGH 8.8
CVE-2023-28019

Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL …

Fix: 14+
Fix from $1,950 2023-07-18
Bigfix Webui Insights MEDIUM 6.5
CVE-2023-23344

A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.

Mitigation only
Fix from $1,600 2023-06-23
Bigfix Osd Bare Metal Server HIGH 7.8
CVE-2023-28006

The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.

Fix: after 311.12
Fix from $1,950 2023-06-22
Bigfix Osd Bare Metal Server MEDIUM 6.1
CVE-2023-28016

Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause …

Fix: after 311.12
Fix from $1,600 2023-06-22
Bigfix Osd Bare Metal Server MEDIUM 6.1
CVE-2023-23343

A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to t…

Fix: after 311.12
Fix from $1,600 2023-06-22
Workload Automation HIGH 8.1
CVE-2023-28008

HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacke…

Mitigation only
Fix from $1,950 2023-04-26
Workload Automation HIGH 8.1
CVE-2023-28009

HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this…

Mitigation only
Fix from $1,950 2023-04-26
Hcl Compass HIGH 8.8
CVE-2022-42447

HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate…

Fix: 2.2.1+
Fix from $1,950 2023-04-02
Verse MEDIUM 6.1
CVE-2021-27788

HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability.  By tricking a user into clicking a crafted URL, a remote unauthenticated att…

Fix: 3.0+
Fix from $1,600 2023-03-10
Hcl Leap MEDIUM 5.4
CVE-2022-38657

An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.

Fix: 9.3+
Fix from $1,600 2023-02-12
Bigfix Mobile HIGH 7.5
CVE-2021-27782

HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attemp…

Mitigation only
Fix from $1,950 2023-01-20
Bigfix Server Automation HIGH 7.5
CVE-2022-38658

BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in cle…

Fix: after 3.2.1
Fix from $1,950 2022-12-24
Bigfix Webui MEDIUM 5.8
CVE-2022-38655

BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from…

Mitigation only
Fix from $1,600 2022-12-21
Notes HIGH 7.8
CVE-2022-44753

HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticat…

Mitigation only
Fix from $1,950 2022-12-19
Domino HIGH 7.8
CVE-2022-44754

HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticat…

Mitigation only
Fix from $1,950 2022-12-19
Notes HIGH 7.8
CVE-2022-44755

HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticate…

Mitigation only
Fix from $1,950 2022-12-19