Vulnerabilities > Hcltech

DATE CVE VULNERABILITY TITLE RISK
2024-02-09 CVE-2023-45716 Cleartext Transmission of Sensitive Information vulnerability in Hcltech Sametime 11.6/12.0
Sametime is impacted by sensitive information passed in URL.
low complexity
hcltech CWE-319
4.1
2024-02-09 CVE-2023-50349 Cross-Site Request Forgery (CSRF) vulnerability in Hcltech Sametime 11.6/12.0
Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability.
network
low complexity
hcltech CWE-352
8.8
2024-02-03 CVE-2023-37528 Cross-site Scripting vulnerability in Hcltech Bigfix Platform
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.
network
low complexity
hcltech CWE-79
6.1
2024-02-02 CVE-2024-23553 Cross-site Scripting vulnerability in Hcltech Bigfix Platform
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
network
low complexity
hcltech CWE-79
5.4
2024-02-02 CVE-2023-37527 Cross-site Scripting vulnerability in Hcltech Bigfix Platform
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.
network
low complexity
hcltech CWE-79
6.1
2024-01-30 CVE-2023-37518 Code Injection vulnerability in Hcltech Bigfix Servicenow Data Flow 1.2
HCL BigFix ServiceNow is vulnerable to arbitrary code injection.
network
low complexity
hcltech CWE-94
8.8
2024-01-03 CVE-2023-45722 Path Traversal vulnerability in Hcltech Dryice Myxalytics 5.9/6.0/6.1
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.
network
low complexity
hcltech CWE-22
critical
9.8
2024-01-03 CVE-2023-45723 Path Traversal vulnerability in Hcltech Dryice Myxalytics 5.9/6.0/6.1
HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.
network
low complexity
hcltech CWE-22
critical
9.8
2024-01-03 CVE-2023-45724 Unrestricted Upload of File with Dangerous Type vulnerability in Hcltech Dryice Myxalytics 5.9/6.0/6.1
HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability.
network
low complexity
hcltech CWE-434
critical
9.8
2024-01-03 CVE-2023-50341 Unspecified vulnerability in Hcltech Dryice Myxalytics 5.9/6.0/6.1
HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability.
network
low complexity
hcltech
7.5