hcltechsw kayıtları
hcltechsw üreticisine ait 51 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-532 Insertion of Sensitive Information into Log File5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-613 Insufficient Session Expiration3
- CWE-922 Insecure Storage of Sensitive Information3
- CWE-522 Insufficiently Protected Credentials3
- CWE-306 Missing Authentication for Critical Function3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
51 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2020-14275İstismar yok | Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of servichcltechsw · hcl commerce | Kritik9,8 | — | %1,5 | 12 Oca 2021 |
39İzleyin | CVE-2020-14245İstismar yok | HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or conhcltechsw · onetest performance · CWE-306 | Kritik9,8 | — | %1,2 | 4 Şub 2021 |
39İzleyin | CVE-2022-38656İstismar yok | HCL Commerce, when using Elasticsearch, could be affected by a denial of service vulnerabilityhcltechsw · hcl commerce | Kritik9,8 | — | %0,7 | 12 Ara 2022 |
39İzleyin | CVE-2023-37522İstismar yok | HCL BigFix OSD Bare Metal Server WebUI is affected by missing or insecure tagshcltechsw · bigfix bare osd metal server webui | Kritik9,8 | — | %0,4 | 16 Oca 2024 |
39İzleyin | CVE-2023-37523İstismar yok | HCL BigFix OSD Bare Metal Server WebUI is affected by missing or insecure tagshcltechsw · bigfix bare osd metal server webui · CWE-79 | Kritik9,8 | — | %0,4 | 16 Oca 2024 |
36İzleyin | CVE-2021-27741İstismar yok | " Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"hcltechsw · hcl commerce · CWE-611 | Kritik9,1 | — | %1,2 | 13 Ağu 2021 |
35İzleyin | CVE-2020-14231İstismar yok | A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attachcltechsw · hcl client application access · CWE-20 | Yüksek8,8 | — | %1,0 | 22 Ara 2020 |
30İzleyin | CVE-2020-14274İstismar yok | Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain hcltechsw · hcl commerce | Yüksek7,5 | — | %1,3 | 12 Oca 2021 |
30İzleyin | CVE-2020-14246İstismar yok | HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak.hcltechsw · onetest performance · CWE-327 | Yüksek7,5 | — | %0,7 | 4 Şub 2021 |
30İzleyin | CVE-2023-45703İstismar yok | HCL Launch is susceptible to a Denial of Service vulnerabilityhcltechsw · hcl launch | Yüksek7,5 | — | %0,5 | 20 Ara 2023 |
30İzleyin | CVE-2025-0257İstismar yok | HCL DevOps Deploy / HCL Launch is susceptible to unauthorized access to other serviceshcltechsw · hcl devops deploy · CWE-306 | Yüksek7,5 | — | %0,3 | 2 Nis 2025 |
30İzleyin | CVE-2026-56458İstismar yok | HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domainshcltechsw · hcl devops deploy · CWE-942 | Yüksek7,5 | — | %0,3 | 9 Tem 2026 |
30İzleyin | CVE-2025-0272İstismar yok | HCL DevOps Deploy / HCL Launch is susceptible to an HTML injection vulnerabilityhcltechsw · hcl devops deploy · CWE-80 | Yüksek7,6 | — | %0,3 | 3 Nis 2025 |
28İzleyin | CVE-2025-0255İstismar yok | HCL DevOps Deploy / HCL Launch is susceptible to command injection vulnerabilityhcltechsw · hcl devops deploy · CWE-78 | Yüksek7,2 | — | %0,7 | 24 Mar 2025 |
28İzleyin | CVE-2024-23576İstismar yok | HCL Commerce is potentially affected by a denial of service and information disclosure vulnerabilityhcltechsw · hcl commerce · CWE-285 | Yüksek7,1 | — | %0,5 | 14 May 2024 |
28İzleyin | CVE-2022-38661İstismar yok | HCL Workload Automation is affected by a vulnerability in Jlog component of the Master Domain Managerhcltechsw · hcl workload automation | Yüksek7,1 | — | %0,2 | 12 Ara 2022 |
27İzleyin | CVE-2024-42195İstismar yok | HCL DevOps Deploy / HCL Launch is vulnerable to HTML injectionhcltechsw · hcl devops deploy · CWE-80 | Orta6,8 | — | %0,3 | 5 Ara 2024 |
26İzleyin | CVE-2020-14225İstismar yok | HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content.hcltech · hcl inotes | Orta6,5 | — | %1,3 | 21 Ara 2020 |
26İzleyin | CVE-2020-14247İstismar yok | HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valhcltechsw · onetest performance · CWE-613 | Orta6,5 | — | %0,7 | 4 Şub 2021 |
26İzleyin | CVE-2022-27551İstismar yok | HCL Launch could allow an authenticated user to obtain sensitive information (CVE-2022-27551)hcltechsw · hcl launch · CWE-863 | Orta6,5 | — | %0,5 | 3 Ağu 2022 |
26İzleyin | CVE-2023-45701İstismar yok | HCL Launch is susceptible to sensitive information disclosurehcltechsw · hcl launch · CWE-209 | Orta6,5 | — | %0,5 | 28 Ara 2023 |
26İzleyin | CVE-2022-44756İstismar yok | HCL BigFix Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validationhcltechsw · bigfix insights for vulnerability remediation · CWE-20 | Orta6,5 | — | %0,4 | 21 Ara 2022 |
26İzleyin | CVE-2026-56460İstismar yok | HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerabilityhcltechsw · hcl devops deploy · CWE-201 | Orta6,5 | — | %0,4 | 9 Tem 2026 |
26İzleyin | CVE-2025-0256İstismar yok | HCL DevOps Deploy / HCL Launch is susceptible to a sensitive information disclosurehcltechsw · hcl devops deploy · CWE-306 | Orta6,5 | — | %0,3 | 24 Mar 2025 |
25İzleyin | CVE-2024-23558İstismar yok | HCL DevOps Deploy / HCL Launch does not invalidate all session authentication cookies after logouthcltechsw · hcl devops deploy · CWE-290 | Orta6,3 | — | %0,3 | 15 Nis 2024 |
- CVE-2020-1427539İzleyin
Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of servic
KritikCVSS 9,8İstismar yokEPSS %1hcltechsw · hcl commerce12 Oca 2021
- CVE-2020-1424539İzleyin
HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or con
KritikCVSS 9,8İstismar yokEPSS %1hcltechsw · onetest performance4 Şub 2021
- CVE-2022-3865639İzleyin
HCL Commerce, when using Elasticsearch, could be affected by a denial of service vulnerability
KritikCVSS 9,8İstismar yokEPSS %1hcltechsw · hcl commerce12 Ara 2022
- CVE-2023-3752239İzleyin
HCL BigFix OSD Bare Metal Server WebUI is affected by missing or insecure tags
KritikCVSS 9,8İstismar yokEPSS %0hcltechsw · bigfix bare osd metal server webui16 Oca 2024
- CVE-2023-3752339İzleyin
HCL BigFix OSD Bare Metal Server WebUI is affected by missing or insecure tags
KritikCVSS 9,8İstismar yokEPSS %0hcltechsw · bigfix bare osd metal server webui16 Oca 2024
- CVE-2021-2774136İzleyin
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
KritikCVSS 9,1İstismar yokEPSS %1hcltechsw · hcl commerce13 Ağu 2021
- CVE-2020-1423135İzleyin
A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attac
YüksekCVSS 8,8İstismar yokEPSS %1hcltechsw · hcl client application access22 Ara 2020
- CVE-2020-1427430İzleyin
Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain
YüksekCVSS 7,5İstismar yokEPSS %1hcltechsw · hcl commerce12 Oca 2021
- CVE-2020-1424630İzleyin
HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak.
YüksekCVSS 7,5İstismar yokEPSS %1hcltechsw · onetest performance4 Şub 2021
- CVE-2023-4570330İzleyin
HCL Launch is susceptible to a Denial of Service vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0hcltechsw · hcl launch20 Ara 2023
- CVE-2025-025730İzleyin
HCL DevOps Deploy / HCL Launch is susceptible to unauthorized access to other services
YüksekCVSS 7,5İstismar yokEPSS %0hcltechsw · hcl devops deploy2 Nis 2025
- CVE-2026-5645830İzleyin
HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains
YüksekCVSS 7,5İstismar yokEPSS %0hcltechsw · hcl devops deploy9 Tem 2026
- CVE-2025-027230İzleyin
HCL DevOps Deploy / HCL Launch is susceptible to an HTML injection vulnerability
YüksekCVSS 7,6İstismar yokEPSS %0hcltechsw · hcl devops deploy3 Nis 2025
- CVE-2025-025528İzleyin
HCL DevOps Deploy / HCL Launch is susceptible to command injection vulnerability
YüksekCVSS 7,2İstismar yokEPSS %1hcltechsw · hcl devops deploy24 Mar 2025
- CVE-2024-2357628İzleyin
HCL Commerce is potentially affected by a denial of service and information disclosure vulnerability
YüksekCVSS 7,1İstismar yokEPSS %0hcltechsw · hcl commerce14 May 2024
- CVE-2022-3866128İzleyin
HCL Workload Automation is affected by a vulnerability in Jlog component of the Master Domain Manager
YüksekCVSS 7,1İstismar yokEPSS %0hcltechsw · hcl workload automation12 Ara 2022
- CVE-2024-4219527İzleyin
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection
OrtaCVSS 6,8İstismar yokEPSS %0hcltechsw · hcl devops deploy5 Ara 2024
- CVE-2020-1422526İzleyin
HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content.
OrtaCVSS 6,5İstismar yokEPSS %1hcltech · hcl inotes21 Ara 2020
- CVE-2020-1424726İzleyin
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a val
OrtaCVSS 6,5İstismar yokEPSS %1hcltechsw · onetest performance4 Şub 2021
- CVE-2022-2755126İzleyin
HCL Launch could allow an authenticated user to obtain sensitive information (CVE-2022-27551)
OrtaCVSS 6,5İstismar yokEPSS %1hcltechsw · hcl launch3 Ağu 2022
- CVE-2023-4570126İzleyin
HCL Launch is susceptible to sensitive information disclosure
OrtaCVSS 6,5İstismar yokEPSS %0hcltechsw · hcl launch28 Ara 2023
- CVE-2022-4475626İzleyin
HCL BigFix Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation
OrtaCVSS 6,5İstismar yokEPSS %0hcltechsw · bigfix insights for vulnerability remediation21 Ara 2022
- CVE-2026-5646026İzleyin
HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0hcltechsw · hcl devops deploy9 Tem 2026
- CVE-2025-025626İzleyin
HCL DevOps Deploy / HCL Launch is susceptible to a sensitive information disclosure
OrtaCVSS 6,5İstismar yokEPSS %0hcltechsw · hcl devops deploy24 Mar 2025
- CVE-2024-2355825İzleyin
HCL DevOps Deploy / HCL Launch does not invalidate all session authentication cookies after logout
OrtaCVSS 6,3İstismar yokEPSS %0hcltechsw · hcl devops deploy15 Nis 2024