Записи hcltechsw
51 опубликованных записей вендора hcltechsw.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-532 Insertion of Sensitive Information into Log File5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-613 Insufficient Session Expiration3
- CWE-922 Insecure Storage of Sensitive Information3
- CWE-522 Insufficiently Protected Credentials3
- CWE-306 Missing Authentication for Critical Function3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
51 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2020-14275Эксплойта нет | Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of servichcltechsw · hcl commerce | Критическая9,8 | — | 1,5 % | 12 янв. 2021 г. |
39Наблюдать | CVE-2020-14245Эксплойта нет | HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or conhcltechsw · onetest performance · CWE-306 | Критическая9,8 | — | 1,2 % | 4 февр. 2021 г. |
39Наблюдать | CVE-2022-38656Эксплойта нет | HCL Commerce, when using Elasticsearch, could be affected by a denial of service vulnerabilityhcltechsw · hcl commerce | Критическая9,8 | — | 0,7 % | 12 дек. 2022 г. |
39Наблюдать | CVE-2023-37522Эксплойта нет | HCL BigFix OSD Bare Metal Server WebUI is affected by missing or insecure tagshcltechsw · bigfix bare osd metal server webui | Критическая9,8 | — | 0,4 % | 16 янв. 2024 г. |
39Наблюдать | CVE-2023-37523Эксплойта нет | HCL BigFix OSD Bare Metal Server WebUI is affected by missing or insecure tagshcltechsw · bigfix bare osd metal server webui · CWE-79 | Критическая9,8 | — | 0,4 % | 16 янв. 2024 г. |
36Наблюдать | CVE-2021-27741Эксплойта нет | " Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"hcltechsw · hcl commerce · CWE-611 | Критическая9,1 | — | 1,2 % | 13 авг. 2021 г. |
35Наблюдать | CVE-2020-14231Эксплойта нет | A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attachcltechsw · hcl client application access · CWE-20 | Высокая8,8 | — | 1,0 % | 22 дек. 2020 г. |
30Наблюдать | CVE-2020-14274Эксплойта нет | Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain hcltechsw · hcl commerce | Высокая7,5 | — | 1,3 % | 12 янв. 2021 г. |
30Наблюдать | CVE-2020-14246Эксплойта нет | HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak.hcltechsw · onetest performance · CWE-327 | Высокая7,5 | — | 0,7 % | 4 февр. 2021 г. |
30Наблюдать | CVE-2023-45703Эксплойта нет | HCL Launch is susceptible to a Denial of Service vulnerabilityhcltechsw · hcl launch | Высокая7,5 | — | 0,5 % | 20 дек. 2023 г. |
30Наблюдать | CVE-2025-0257Эксплойта нет | HCL DevOps Deploy / HCL Launch is susceptible to unauthorized access to other serviceshcltechsw · hcl devops deploy · CWE-306 | Высокая7,5 | — | 0,3 % | 2 апр. 2025 г. |
30Наблюдать | CVE-2026-56458Эксплойта нет | HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domainshcltechsw · hcl devops deploy · CWE-942 | Высокая7,5 | — | 0,3 % | 9 июл. 2026 г. |
30Наблюдать | CVE-2025-0272Эксплойта нет | HCL DevOps Deploy / HCL Launch is susceptible to an HTML injection vulnerabilityhcltechsw · hcl devops deploy · CWE-80 | Высокая7,6 | — | 0,3 % | 3 апр. 2025 г. |
28Наблюдать | CVE-2025-0255Эксплойта нет | HCL DevOps Deploy / HCL Launch is susceptible to command injection vulnerabilityhcltechsw · hcl devops deploy · CWE-78 | Высокая7,2 | — | 0,7 % | 24 мар. 2025 г. |
28Наблюдать | CVE-2024-23576Эксплойта нет | HCL Commerce is potentially affected by a denial of service and information disclosure vulnerabilityhcltechsw · hcl commerce · CWE-285 | Высокая7,1 | — | 0,5 % | 14 мая 2024 г. |
28Наблюдать | CVE-2022-38661Эксплойта нет | HCL Workload Automation is affected by a vulnerability in Jlog component of the Master Domain Managerhcltechsw · hcl workload automation | Высокая7,1 | — | 0,2 % | 12 дек. 2022 г. |
27Наблюдать | CVE-2024-42195Эксплойта нет | HCL DevOps Deploy / HCL Launch is vulnerable to HTML injectionhcltechsw · hcl devops deploy · CWE-80 | Средняя6,8 | — | 0,3 % | 5 дек. 2024 г. |
26Наблюдать | CVE-2020-14225Эксплойта нет | HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content.hcltech · hcl inotes | Средняя6,5 | — | 1,3 % | 21 дек. 2020 г. |
26Наблюдать | CVE-2020-14247Эксплойта нет | HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valhcltechsw · onetest performance · CWE-613 | Средняя6,5 | — | 0,7 % | 4 февр. 2021 г. |
26Наблюдать | CVE-2022-27551Эксплойта нет | HCL Launch could allow an authenticated user to obtain sensitive information (CVE-2022-27551)hcltechsw · hcl launch · CWE-863 | Средняя6,5 | — | 0,5 % | 3 авг. 2022 г. |
26Наблюдать | CVE-2023-45701Эксплойта нет | HCL Launch is susceptible to sensitive information disclosurehcltechsw · hcl launch · CWE-209 | Средняя6,5 | — | 0,5 % | 28 дек. 2023 г. |
26Наблюдать | CVE-2022-44756Эксплойта нет | HCL BigFix Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validationhcltechsw · bigfix insights for vulnerability remediation · CWE-20 | Средняя6,5 | — | 0,4 % | 21 дек. 2022 г. |
26Наблюдать | CVE-2026-56460Эксплойта нет | HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerabilityhcltechsw · hcl devops deploy · CWE-201 | Средняя6,5 | — | 0,4 % | 9 июл. 2026 г. |
26Наблюдать | CVE-2025-0256Эксплойта нет | HCL DevOps Deploy / HCL Launch is susceptible to a sensitive information disclosurehcltechsw · hcl devops deploy · CWE-306 | Средняя6,5 | — | 0,3 % | 24 мар. 2025 г. |
25Наблюдать | CVE-2024-23558Эксплойта нет | HCL DevOps Deploy / HCL Launch does not invalidate all session authentication cookies after logouthcltechsw · hcl devops deploy · CWE-290 | Средняя6,3 | — | 0,3 % | 15 апр. 2024 г. |
- CVE-2020-1427539Наблюдать
Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of servic
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltechsw · hcl commerce12 янв. 2021 г.
- CVE-2020-1424539Наблюдать
HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or con
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltechsw · onetest performance4 февр. 2021 г.
- CVE-2022-3865639Наблюдать
HCL Commerce, when using Elasticsearch, could be affected by a denial of service vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltechsw · hcl commerce12 дек. 2022 г.
- CVE-2023-3752239Наблюдать
HCL BigFix OSD Bare Metal Server WebUI is affected by missing or insecure tags
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltechsw · bigfix bare osd metal server webui16 янв. 2024 г.
- CVE-2023-3752339Наблюдать
HCL BigFix OSD Bare Metal Server WebUI is affected by missing or insecure tags
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltechsw · bigfix bare osd metal server webui16 янв. 2024 г.
- CVE-2021-2774136Наблюдать
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %hcltechsw · hcl commerce13 авг. 2021 г.
- CVE-2020-1423135Наблюдать
A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attac
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hcltechsw · hcl client application access22 дек. 2020 г.
- CVE-2020-1427430Наблюдать
Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %hcltechsw · hcl commerce12 янв. 2021 г.
- CVE-2020-1424630Наблюдать
HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %hcltechsw · onetest performance4 февр. 2021 г.
- CVE-2023-4570330Наблюдать
HCL Launch is susceptible to a Denial of Service vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %hcltechsw · hcl launch20 дек. 2023 г.
- CVE-2025-025730Наблюдать
HCL DevOps Deploy / HCL Launch is susceptible to unauthorized access to other services
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %hcltechsw · hcl devops deploy2 апр. 2025 г.
- CVE-2026-5645830Наблюдать
HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %hcltechsw · hcl devops deploy9 июл. 2026 г.
- CVE-2025-027230Наблюдать
HCL DevOps Deploy / HCL Launch is susceptible to an HTML injection vulnerability
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %hcltechsw · hcl devops deploy3 апр. 2025 г.
- CVE-2025-025528Наблюдать
HCL DevOps Deploy / HCL Launch is susceptible to command injection vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %hcltechsw · hcl devops deploy24 мар. 2025 г.
- CVE-2024-2357628Наблюдать
HCL Commerce is potentially affected by a denial of service and information disclosure vulnerability
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %hcltechsw · hcl commerce14 мая 2024 г.
- CVE-2022-3866128Наблюдать
HCL Workload Automation is affected by a vulnerability in Jlog component of the Master Domain Manager
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %hcltechsw · hcl workload automation12 дек. 2022 г.
- CVE-2024-4219527Наблюдать
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection
СредняяCVSS 6,8Эксплойта нетEPSS 0 %hcltechsw · hcl devops deploy5 дек. 2024 г.
- CVE-2020-1422526Наблюдать
HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %hcltech · hcl inotes21 дек. 2020 г.
- CVE-2020-1424726Наблюдать
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a val
СредняяCVSS 6,5Эксплойта нетEPSS 1 %hcltechsw · onetest performance4 февр. 2021 г.
- CVE-2022-2755126Наблюдать
HCL Launch could allow an authenticated user to obtain sensitive information (CVE-2022-27551)
СредняяCVSS 6,5Эксплойта нетEPSS 1 %hcltechsw · hcl launch3 авг. 2022 г.
- CVE-2023-4570126Наблюдать
HCL Launch is susceptible to sensitive information disclosure
СредняяCVSS 6,5Эксплойта нетEPSS 0 %hcltechsw · hcl launch28 дек. 2023 г.
- CVE-2022-4475626Наблюдать
HCL BigFix Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation
СредняяCVSS 6,5Эксплойта нетEPSS 0 %hcltechsw · bigfix insights for vulnerability remediation21 дек. 2022 г.
- CVE-2026-5646026Наблюдать
HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerability
СредняяCVSS 6,5Эксплойта нетEPSS 0 %hcltechsw · hcl devops deploy9 июл. 2026 г.
- CVE-2025-025626Наблюдать
HCL DevOps Deploy / HCL Launch is susceptible to a sensitive information disclosure
СредняяCVSS 6,5Эксплойта нетEPSS 0 %hcltechsw · hcl devops deploy24 мар. 2025 г.
- CVE-2024-2355825Наблюдать
HCL DevOps Deploy / HCL Launch does not invalidate all session authentication cookies after logout
СредняяCVSS 6,3Эксплойта нетEPSS 0 %hcltechsw · hcl devops deploy15 апр. 2024 г.