HCL Launch stores user credentials in plain clear text which can be read by a local user.
HCL Launch may store certain data for recurring activities in a plain text format.
"HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability"
HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a s…
HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded crede…
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid sessio…
A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resul…