Vulnerabilities > Hcltech

DATE CVE VULNERABILITY TITLE RISK
2025-01-11 CVE-2024-42173 Weak Password Requirements vulnerability in Hcltech Dryice Myxalytics 6.3
HCL MyXalytics is affected by an improper password policy implementation vulnerability.
network
high complexity
hcltech CWE-521
4.8
2025-01-11 CVE-2024-42174 Information Exposure Through Discrepancy vulnerability in Hcltech Dryice Myxalytics 6.3
HCL MyXalytics is affected by username enumeration vulnerability.
network
high complexity
hcltech CWE-203
3.7
2025-01-11 CVE-2024-42168 Server-Side Request Forgery (SSRF) vulnerability in Hcltech Dryice Myxalytics 6.3
HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability.
network
low complexity
hcltech CWE-918
critical
9.4
2025-01-11 CVE-2024-42169 Authorization Bypass Through User-Controlled Key vulnerability in Hcltech Dryice Myxalytics 6.3
HCL MyXalytics is affected by insecure direct object references.
network
low complexity
hcltech CWE-639
8.1
2024-10-28 CVE-2024-30106 Unspecified vulnerability in Hcltech Connections 7.0/8.0
HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entitled to due to the improper handling of request data.
network
low complexity
hcltech
4.3
2024-10-23 CVE-2023-50355 Information Exposure Through an Error Message vulnerability in Hcltech Sametime 11.6/12.0/12.0.2
HCL Sametime is impacted by the error messages containing sensitive information.
network
low complexity
hcltech CWE-209
5.3
2024-10-23 CVE-2024-30122 Unspecified vulnerability in Hcltech Sametime 11.6/12.0/12.0.2
HCL Sametime is impacted by misconfigured security related HTTP headers.
network
low complexity
hcltech
5.3
2024-10-14 CVE-2024-30117 Uncontrolled Search Path Element vulnerability in Hcltech Bigfix Platform
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.
network
low complexity
hcltech CWE-427
5.3
2024-10-09 CVE-2024-30118 Unspecified vulnerability in Hcltech Connections 7.0/8.0
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly handling the request data.
network
low complexity
hcltech
5.7
2024-09-27 CVE-2024-23586 Insufficient Session Expiration vulnerability in Hcltech HCL Nomad
HCL Nomad is susceptible to an insufficient session expiration vulnerability.
network
low complexity
hcltech CWE-613
7.5