HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to fi…
HCL Launch stores user credentials in plain clear text which can be read by a local user.
HCL Launch may store certain data for recurring activities in a plain text format.
"HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability"
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a s…
HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded crede…
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid sessio…
Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclo…
Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user pers…
A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resul…