Vulnerabilities > Hcltechsw

DATE CVE VULNERABILITY TITLE RISK
2024-02-03 CVE-2024-23550 Unspecified vulnerability in Hcltechsw HCL Devops Deploy and HCL Launch
HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.
local
low complexity
hcltechsw
5.5
2024-01-16 CVE-2023-37523 Unspecified vulnerability in Hcltechsw Bigfix Bare OSD Metal Server Webui 311.19
Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.
network
low complexity
hcltechsw
critical
9.8
2024-01-16 CVE-2023-37521 Unspecified vulnerability in Hcltechsw Bigfix Bare OSD Metal Server Webui 311.19
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker to execute a malicious attack.
network
low complexity
hcltechsw
5.3
2024-01-16 CVE-2023-37522 Unspecified vulnerability in Hcltechsw Bigfix Bare OSD Metal Server Webui 311.19
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.
network
low complexity
hcltechsw
critical
9.8
2023-12-28 CVE-2023-45702 Unspecified vulnerability in Hcltechsw HCL Launch
An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts..
local
low complexity
hcltechsw
5.5
2023-12-28 CVE-2023-45701 Information Exposure Through an Error Message vulnerability in Hcltechsw HCL Launch
HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
hcltechsw CWE-209
6.5
2023-12-21 CVE-2023-45700 Cross-site Scripting vulnerability in Hcltechsw HCL Launch
HCL Launch is vulnerable to HTML injection.
network
low complexity
hcltechsw CWE-79
5.4
2023-12-21 CVE-2023-45703 Unspecified vulnerability in Hcltechsw HCL Launch
HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion.
network
low complexity
hcltechsw
7.5
2023-07-10 CVE-2023-23348 Unspecified vulnerability in Hcltechsw HCL Launch
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.
local
low complexity
hcltechsw
5.5
2023-04-02 CVE-2022-42452 Cross-site Scripting vulnerability in Hcltechsw HCL Launch
HCL Launch is vulnerable to HTML injection.
network
low complexity
hcltechsw CWE-79
5.4