Vulnerabilities > Hcltech

DATE CVE VULNERABILITY TITLE RISK
2024-07-08 CVE-2024-23562 Unspecified vulnerability in Hcltech Domino 11.0/12.0/14.0
This vulnerability is being re-assessed.  Vulnerability details will be updated. The security bulletin will be republished when further details are available.
network
low complexity
hcltech
7.5
2024-07-05 CVE-2024-23588 Unspecified vulnerability in Hcltech Nomad Server on Domino
HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.
network
low complexity
hcltech
6.5
2024-06-06 CVE-2023-37539 Cross-site Scripting vulnerability in Hcltech Domino 11.0/12.0/14.0
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.
network
low complexity
hcltech CWE-79
5.4
2024-02-10 CVE-2023-45696 Unspecified vulnerability in Hcltech Sametime 11.6/12.0
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client.
network
low complexity
hcltech
7.5
2024-02-09 CVE-2023-45716 Cleartext Transmission of Sensitive Information vulnerability in Hcltech Sametime 11.6/12.0
Sametime is impacted by sensitive information passed in URL.
low complexity
hcltech CWE-319
4.1
2024-02-09 CVE-2023-45718 Session Fixation vulnerability in Hcltech Sametime 11.6/12.0
Sametime is impacted by a failure to invalidate sessions.
network
low complexity
hcltech CWE-384
7.5
2024-02-09 CVE-2023-50349 Cross-Site Request Forgery (CSRF) vulnerability in Hcltech Sametime 11.6/12.0
Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability.
network
low complexity
hcltech CWE-352
8.8
2024-02-03 CVE-2023-37528 Cross-site Scripting vulnerability in Hcltech Bigfix Platform
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.
network
low complexity
hcltech CWE-79
6.1
2024-02-02 CVE-2024-23553 Cross-site Scripting vulnerability in Hcltech Bigfix Platform
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
network
low complexity
hcltech CWE-79
5.4
2024-02-02 CVE-2023-37527 Cross-site Scripting vulnerability in Hcltech Bigfix Platform
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.
network
low complexity
hcltech CWE-79
6.1