Loading HuntDB...

Vulnerabilities

CVE-2024-30129

MEDIUM

The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would cause the request to be sent to a completely different domain/IP address.

Published Dec 06, 2024

CVE-2024-23586

MEDIUM

HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.

Published Sep 27, 2024

CVE-2024-30134

MEDIUM

The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application.

Published Sep 26, 2024

CVE-2024-30128

HIGH

HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker to trick the user into exposing sensitive information.

Published Sep 25, 2024

CVE-2024-23562

MEDIUM

A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain information to launch further attacks against the affected system.

Published Jul 08, 2024

CVE-2023-37539

HIGH

The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it.

Published Jun 06, 2024

CVE-2024-23556

MEDIUM

SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.

Published May 17, 2024

CVE-2024-23554

MEDIUM

Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).

Published May 17, 2024

CVE-2024-23583

MEDIUM

An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.

Published May 17, 2024

CVE-2023-37526

MEDIUM

HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which could potentially allow unauthorized access to the application resources from any web domain and enable cache poisoning attacks.

Published May 10, 2024

CVE-2024-23551

MEDIUM

Database scanning using username and password stores the credentials in plaintext or encoded format within files at the endpoint. This has been identified as a significant security risk. This will lead to exposure of sensitive information for unauthorized access, potentially leading to severe consequences such as data breaches, unauthorized data manipulation, and compromised system integrity.

Published May 07, 2024

CVE-2024-30107

LOW

HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.

Published Apr 18, 2024

CVE-2024-23584

MEDIUM

The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.

Published Apr 08, 2024

CVE-2024-23540

MEDIUM

The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file.

Published Apr 03, 2024

CVE-2023-37536

HIGH

An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

Published Oct 11, 2023