Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

HCL Software — Vulnerabilities & Security Advisories 353

Browse all 353 CVE security advisories affecting HCL Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HCL Software specializes in enterprise application development and management tools, primarily serving large organizations with legacy and modernization needs. Its portfolio includes Domino, OpenPages, and various integration platforms, which historically present a diverse attack surface. Common vulnerability classes affecting these products include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configurations or outdated underlying frameworks. The company has addressed numerous security flaws, with records indicating hundreds of disclosed CVEs over the years. Notable incidents have involved authentication bypasses and injection flaws in older versions of its collaboration suites. HCL Software generally responds to these issues through regular patch cycles and security advisories, though the sheer volume of legacy code contributes to the high number of recorded vulnerabilities. Users are advised to maintain strict update protocols to mitigate risks associated with these known security gaps.

CVE IDTitleCVSSSeverityPublished
CVE-2026-56609 HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609). — HCL iControlCWE-327 4.8 Medium2026-08-03
CVE-2026-56608 HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609). — HCL iControlCWE-284 3.7 Low2026-08-03
CVE-2026-56571 HCL iControl is affected by multiple security vulnerabilities. — HCL iControlCWE-209 3.7 Low2026-07-31
CVE-2026-56570 HCL iControl is affected by multiple security vulnerabilities. — HCL iControlCWE-522 3.7 Low2026-07-31
CVE-2026-56569 HCL iControl is affected by multiple security vulnerabilities. — HCL iControlCWE-497 4.0 Medium2026-07-31
CVE-2026-56568 HCL iControl is affected by multiple security vulnerabilities. — HCL iControlCWE-209 3.7 Low2026-07-31
CVE-2026-56567 HCL iControl is affected by multiple security vulnerabilities. — HCL iControlCWE-15 5.1 Medium2026-07-31
CVE-2024-23564 HCL Aftermarket EPC 加密问题漏洞 — Aftermarket EPCCWE-326 9.1 Critical2026-07-17
CVE-2026-56456 HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. — DFXAnalyticsCWE-200 5.3 Medium2026-07-16
CVE-2026-56455 HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). — DFXAnalyticsCWE-121 5.3 Medium2026-07-16
CVE-2026-56454 HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. — DFXAnalyticsCWE-327 5.9 Medium2026-07-16
CVE-2026-56453 HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. — DFXAnalyticsCWE-294 5.5 Medium2026-07-16
CVE-2026-35145 HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. — DFXAnalyticsCWE-200 3.1 Low2026-07-16
CVE-2026-35143 HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. — DFXAnalyticsCWE-200 3.0 Low2026-07-16
CVE-2026-35142 HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. — DFXAnalyticsCWE-200 2.6 Low2026-07-16
CVE-2026-35141 HCL DFXAnalytics is affected by a Login Replay Attack vulnerability — DFXAnalyticsCWE-294 2.6 Low2026-07-16
CVE-2026-35140 HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability — DFXAnalyticsCWE-200 3.0 Low2026-07-16
CVE-2026-35147 HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. — DFXServerCWE-639 8.2 High2026-07-16
CVE-2026-35149 HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. — DFXServerCWE-294 8.2 High2026-07-16
CVE-2026-35148 HCL DFXServer is affected by a Missing Access Control vulnerability — DFXServerCWE-284 6.3 Medium2026-07-16
CVE-2026-9007 Reflected XSS in HCL Notes — HCL NotesCWE-79--2026-07-15
CVE-2025-59872 HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, — ZIECWE-209 4.3 Medium2026-06-17
CVE-2025-62340 HCL iControl was affected by Inadequate Session Timeout vulnerability — iControlCWE-613 3.1 Low2026-06-17
CVE-2025-31974 HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only — BigFix Service Management (SM)CWE-1188 3.9 Low2026-05-06
CVE-2025-31976 HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials — BigFix Service Management (SM)CWE-200 4.8 Medium2026-05-06
CVE-2025-31978 HCL BigFix Service Management (SM) does not adequately sanitize or safely render — BigFix Service Management (SM)CWE-201 4.6 Medium2026-05-06
CVE-2025-31959 HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. — BigFix Service Management (SM)CWE-1230 3.5 Low2026-05-06
CVE-2025-31982 HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directl — BigFix Service Management (SM)CWE-200 3.7 Low2026-05-06
CVE-2025-31957 HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. — BigFix Service Management (SM)CWE-352 2.6 Low2026-05-06
CVE-2025-59873 Session Token Exposure via URL Query Parameters — ZIE for Web 5.9 Medium2026-02-23

This page lists every published CVE security advisory associated with HCL Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.