Vulnerabilities > Hcltech > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-07 CVE-2023-28017 Cross-site Scripting vulnerability in Hcltech Connections
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code.
network
low complexity
hcltech CWE-79
5.4
2023-11-09 CVE-2023-37533 Cross-site Scripting vulnerability in Hcltech Connections 8.0
HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code.
network
low complexity
hcltech CWE-79
6.1
2023-10-23 CVE-2023-37532 Path Traversal vulnerability in Hcltech Commerce 9.1.13.2/9.1.8
HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.
network
low complexity
hcltech CWE-22
4.3
2023-10-19 CVE-2023-37504 Insufficient Session Expiration vulnerability in Hcltech HCL Compass
HCL Compass is vulnerable to failure to invalidate sessions.
network
low complexity
hcltech CWE-613
6.5
2023-10-11 CVE-2023-37538 Cross-site Scripting vulnerability in Hcltech Digital Experience 8.5/9.0/9.5
HCL Digital Experience is susceptible to cross site scripting (XSS).
network
low complexity
hcltech CWE-79
6.1
2023-10-11 CVE-2022-44758 Insufficiently Protected Credentials vulnerability in Hcltech Bigfix Insights for vulnerability Remediation 2.0/2.0.2
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content.
network
low complexity
hcltech CWE-522
5.3
2023-10-11 CVE-2022-42451 Insufficiently Protected Credentials vulnerability in Hcltech Bigfix Patch Management 1054
Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.
local
low complexity
hcltech CWE-522
4.4
2023-09-08 CVE-2023-28010 Unspecified vulnerability in Hcltech Domino 12.0.2
In some configuration scenarios, the Domino server host name can be exposed.
network
low complexity
hcltech
5.3
2023-08-11 CVE-2023-37511 Unspecified vulnerability in Hcltech Traveler to DO
If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved.
network
low complexity
hcltech
4.3
2023-08-11 CVE-2023-37512 Unspecified vulnerability in Hcltech Traveler Companion
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
local
low complexity
hcltech
5.5