Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

HCL Software — Vulnerabilities & Security Advisories 330

Browse all 330 CVE security advisories affecting HCL Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HCL Software specializes in enterprise application development and management tools, primarily serving large organizations with legacy and modernization needs. Its portfolio includes Domino, OpenPages, and various integration platforms, which historically present a diverse attack surface. Common vulnerability classes affecting these products include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configurations or outdated underlying frameworks. The company has addressed numerous security flaws, with records indicating hundreds of disclosed CVEs over the years. Notable incidents have involved authentication bypasses and injection flaws in older versions of its collaboration suites. HCL Software generally responds to these issues through regular patch cycles and security advisories, though the sheer volume of legacy code contributes to the high number of recorded vulnerabilities. Users are advised to maintain strict update protocols to mitigate risks associated with these known security gaps.

Found 21 results / 330Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2024-30117 HCL BigFix Platform is affected by a DLL Hijack vulnerability — BigFix PlatformCWE-427 2.5 Low2024-10-14
CVE-2024-23556 HCL BigFix Platform is impacted by a failure to restrict SSL/TLS renegotiation — BigFix Platform 5.9 Medium2024-05-17
CVE-2024-23554 HCL BigFix Platform is susceptible to Cross-Site Request Forgery — BigFix PlatformCWE-352 5.7 Medium2024-05-17
CVE-2024-23583 HCL BigFix Platform is susceptible to insufficiently protected credentials — BigFix PlatformCWE-522 6.7 Medium2024-05-17
CVE-2023-45715 HCL BigFix Platform is susceptible to a Denial of Service attack — BigFix Platform 3.5 Low2024-03-28
CVE-2023-45706 HCL BigFix Platform is susceptible to Cross Site Scripting (XSS) and/or Man in the Middle (MITM) attack — BigFix Platform 2.0 Low2024-03-28
CVE-2023-45705 HCL BigFix Platform is susceptible to Server Side Request Forgery (SSRF) — BigFix Platform 3.5 Low2024-03-28
CVE-2023-37528 A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform — BigFix Platform 6.5 Medium2024-02-03
CVE-2024-23553 A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform — BigFix Platform 3.0 Low2024-02-02
CVE-2023-37531 A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform — BigFix Platform 3.3 Low2024-02-02
CVE-2023-37530 A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform — BigFix Platform 3.0 Low2024-02-02
CVE-2023-37529 A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform — BigFix Platform 3.0 Low2024-02-02
CVE-2023-37527 A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform — BigFix Platform 5.4 Medium2024-02-02
CVE-2023-37536 HCL BigFix Platform is vulnerable to an integer overflow in xerces-c++ 3.2.3 — BigFix Platform 8.2 High2023-10-11
CVE-2022-42453 HCL BigFix Platform is affected by insufficient warnings — BigFix Platform 6.9 Medium2022-12-17
CVE-2022-38659 HCL BigFix Platform is affected by insecure credential storage — BigFix Platform 6.0 Medium2022-12-17
CVE-2021-27767 HCL BigFix Platform Console is affected by a Privilege Escalation Vulnerability — BigFix PlatformCWE-269 6.7 Medium2022-05-06
CVE-2021-27766 HCL BigFix Platform Client is affected by a Privilege Escalation Vulnerability — BigFix PlatformCWE-269 6.7 Medium2022-05-06
CVE-2021-27765 HCL BigFix Platform Server API is affected by Privilege Escalation Vulnerability — BigFix PlatformCWE-269 6.7 Medium2022-05-06
CVE-2021-27762 HCL BigFix Platform is affected by misconfigured security-related HTTP headers — BigFix Platform 4.7 Medium2022-05-06
CVE-2021-27761 HCL BigFix Platform is affected by weak web transport security — BigFix Platform 4.8 Medium2022-05-06

This page lists every published CVE security advisory associated with HCL Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.