Vulnerabilities > Hcltechsw > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-28 CVE-2023-45702 Unspecified vulnerability in Hcltechsw HCL Launch
An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts..
local
low complexity
hcltechsw
5.5
2023-12-28 CVE-2023-45701 Information Exposure Through an Error Message vulnerability in Hcltechsw HCL Launch
HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
hcltechsw CWE-209
6.5
2023-12-21 CVE-2023-45700 Cross-site Scripting vulnerability in Hcltechsw HCL Launch
HCL Launch is vulnerable to HTML injection.
network
low complexity
hcltechsw CWE-79
5.4
2023-07-10 CVE-2023-23348 Unspecified vulnerability in Hcltechsw HCL Launch
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.
local
low complexity
hcltechsw
5.5
2023-04-02 CVE-2022-42452 Cross-site Scripting vulnerability in Hcltechsw HCL Launch
HCL Launch is vulnerable to HTML injection.
network
low complexity
hcltechsw CWE-79
5.4
2022-12-21 CVE-2022-42454 Unspecified vulnerability in Hcltechsw Bigfix Insights for vulnerability Remediation
Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure.? This requires privileged network access.
network
high complexity
hcltechsw
5.3
2022-12-21 CVE-2022-44756 Improper Input Validation vulnerability in Hcltechsw Bigfix Insights for vulnerability Remediation
Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation.
network
low complexity
hcltechsw CWE-20
6.5
2022-12-12 CVE-2022-42445 Unspecified vulnerability in Hcltechsw HCL Launch
HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.
network
low complexity
hcltechsw
4.9
2022-08-03 CVE-2022-27551 Incorrect Authorization vulnerability in Hcltechsw HCL Launch
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
network
low complexity
hcltechsw CWE-863
6.5
2022-07-30 CVE-2021-27785 Insufficiently Protected Credentials vulnerability in Hcltechsw HCL Commerce
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information.
local
low complexity
hcltechsw CWE-522
5.0