Loading HuntDB...

Vulnerabilities

CVE-2022-42447

CRITICAL

HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.

Published Mar 27, 2023

CVE-2021-27788

HIGH

HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability.  By tricking a user into clicking a crafted URL, a remote unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.

Published Mar 10, 2023

CVE-2022-38657

HIGH

An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.

Published Feb 02, 2023

CVE-2021-27782

MEDIUM

HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.

Published Jan 19, 2023

CVE-2022-38658

HIGH

BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data exposed.

Published Dec 22, 2022

CVE-2022-38655

MEDIUM

BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.

Published Dec 20, 2022

CVE-2022-44756

MEDIUM

Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires privileged access. 

Published Dec 19, 2022

CVE-2022-42454

MEDIUM

Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure.  This requires privileged network access.

Published Dec 19, 2022

CVE-2022-42453

MEDIUM

There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.

Published Dec 17, 2022

CVE-2022-38659

MEDIUM

In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.

Published Dec 17, 2022

CVE-2022-44754

CRITICAL

HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44750.  This vulnerability applies to software previously licensed by IBM.

Published Dec 17, 2022

CVE-2022-44752

CRITICAL

HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to software previously licensed by IBM.

Published Dec 17, 2022

CVE-2022-44750

CRITICAL

HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44754.  This vulnerability applies to software previously licensed by IBM.

Published Dec 17, 2022

CVE-2022-44755

CRITICAL

HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44751.  This vulnerability applies to software previously licensed by IBM.

Published Dec 17, 2022

CVE-2022-44753

CRITICAL

HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to software previously licensed by IBM.

Published Dec 17, 2022

CVE-2022-44751

CRITICAL

HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755.  This vulnerability applies to software previously licensed by IBM.

Published Dec 17, 2022

CVE-2022-38653

LOW

In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.

Published Dec 15, 2022

CVE-2022-38662

MEDIUM

 In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.

Published Dec 15, 2022

CVE-2022-42446

MEDIUM

Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users.

Published Nov 30, 2022

CVE-2022-42445

MEDIUM

HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.

Published Nov 28, 2022

CVE-2022-38656

HIGH

HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.

Published Nov 04, 2022

CVE-2022-38661

MEDIUM

HCL Workload Automation could allow a local user to overwrite key system files which would cause the system to crash.

Published Nov 04, 2022

CVE-2022-38654

MEDIUM

HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a user's person record.

Published Nov 04, 2022

CVE-2022-38660

HIGH

HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.  

Published Nov 04, 2022

CVE-2020-4099

MEDIUM

The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.

Published Nov 01, 2022

CVE-2021-27784

MEDIUM

The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.

Published Oct 31, 2022

CVE-2021-27774

LOW

User input included in error response, which could be used in a phishing attack.

Published Sep 22, 2022

CVE-2022-27561

HIGH

There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).

Published Sep 15, 2022

CVE-2022-27563

HIGH

An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.

Published Aug 30, 2022

CVE-2022-27560

MEDIUM

HCL VersionVault Express exposes administrator credentials.

Published Aug 30, 2022

CVE-2022-27558

MEDIUM

HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.

Published Aug 29, 2022

CVE-2022-27547

MEDIUM

HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.

Published Aug 29, 2022

CVE-2022-27546

HIGH

HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.

Published Aug 29, 2022

CVE-2022-27551

MEDIUM

HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.

Published Aug 03, 2022

CVE-2021-27785

LOW

HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.

Published Jul 29, 2022

CVE-2022-27545

MEDIUM

BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.

Published Jul 19, 2022

CVE-2022-27544

MEDIUM

BigFix Web Reports authorized users may see SMTP credentials in clear text.

Published Jul 19, 2022

CVE-2022-27549

MEDIUM

HCL Launch may store certain data for recurring activities in a plain text format.

Published Jul 06, 2022

CVE-2022-27548

MEDIUM

HCL Launch stores user credentials in plain clear text which can be read by a local user.

Published Jul 06, 2022

CVE-2021-27786

MEDIUM

Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.

Published Jun 07, 2022

CVE-2021-27778

MEDIUM

HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.

Published May 31, 2022

CVE-2021-27781

MEDIUM

The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.

Published May 27, 2022

CVE-2021-27780

MEDIUM

The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.

Published May 27, 2022

CVE-2021-27783

MEDIUM

User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.

Published May 25, 2022

CVE-2021-27779

CRITICAL

VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.

Published May 25, 2022

CVE-2020-4107

HIGH

HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure.

Published May 19, 2022

CVE-2021-27777

HIGH

XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.

Published May 12, 2022

CVE-2021-27773

MEDIUM

This vulnerability allows users to execute a clickjacking attack in the meeting's chat.

Published May 12, 2022

CVE-2021-27772

HIGH

Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it. This could lead to information leakage where confidential information discussed in private groups is read by other users without the users knowledge.

Published May 12, 2022

CVE-2021-27771

HIGH

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.

Published May 12, 2022