Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

HCL Software — Vulnerabilities & Security Advisories 330

Browse all 330 CVE security advisories affecting HCL Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HCL Software specializes in enterprise application development and management tools, primarily serving large organizations with legacy and modernization needs. Its portfolio includes Domino, OpenPages, and various integration platforms, which historically present a diverse attack surface. Common vulnerability classes affecting these products include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configurations or outdated underlying frameworks. The company has addressed numerous security flaws, with records indicating hundreds of disclosed CVEs over the years. Notable incidents have involved authentication bypasses and injection flaws in older versions of its collaboration suites. HCL Software generally responds to these issues through regular patch cycles and security advisories, though the sheer volume of legacy code contributes to the high number of recorded vulnerabilities. Users are advised to maintain strict update protocols to mitigate risks associated with these known security gaps.

Found 24 results / 330Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2024-42181 HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability — DRYiCE MyXalyticsCWE-319 1.6 Low2025-01-12
CVE-2024-42180 HCL MyXalytics is affected by a malicious file upload vulnerability — DRYiCE MyXalyticsCWE-434 1.6 Low2025-01-12
CVE-2024-42179 HCL MyXalytics is affected by sensitive information disclosure vulnerability — DRYiCE MyXalyticsCWE-200 2.0 Low2025-01-12
CVE-2024-42175 HCL MyXalytics is affected by a weak input validation vulnerability — DRYiCE MyXalyticsCWE-20 2.6 Low2025-01-11
CVE-2024-42174 HCL MyXalytics is affected by username enumeration vulnerability — DRYiCE MyXalyticsCWE-204 3.7 Low2025-01-11
CVE-2024-42173 HCL MyXalytics is affected by an improper password policy implementation vulnerability — DRYiCE MyXalyticsCWE-521 4.8 Medium2025-01-11
CVE-2024-42172 HCL MyXalytics is affected by broken authentication — DRYiCE MyXalyticsCWE-287 5.3 Medium2025-01-11
CVE-2024-42171 HCL MyXalytics is affected by insufficient session expiration — DRYiCE MyXalyticsCWE-384 6.4 Medium2025-01-11
CVE-2024-42170 HCL MyXalytics is affected by a session fixation vulnerability — DRYiCE MyXalyticsCWE-384 6.8 Medium2025-01-11
CVE-2024-42169 HCL MyXalytics is affected by insecure direct object references — DRYiCE MyXalyticsCWE-639 7.1 High2025-01-11
CVE-2024-42168 HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability — DRYiCE MyXalyticsCWE-610 8.9 High2025-01-11
CVE-2023-50347 Insecure SQL Interface affects HCL DRYiCE MyXalytics — DRYiCE MyXalytics 3.7 Low2024-04-10
CVE-2023-45722 Path Traversal Arbitrary File Read affects DRYiCE MyXalytics — DRYiCE MyXalytics 8.8 High2024-01-03
CVE-2023-45724 Unauthenticated File Upload affects DRYiCE MyXalytics — DRYiCE MyXalytics 8.2 High2024-01-03
CVE-2023-45723 Path Traversal which allows file upload capability affects DRYiCE MyXalytics — DRYiCE MyXalytics 7.6 High2024-01-03
CVE-2023-50341 Improper Access Control affects DRYiCE MyXalytics — DRYiCE MyXalytics 7.6 High2024-01-03
CVE-2023-50342 Insecure Direct Object Reference (IDOR) affects DRYiCE MyXalytics — DRYiCE MyXalytics 7.1 High2024-01-03
CVE-2023-50343 Improper Access Control (Controller APIs) affects DRYiCE MyXalytics — DRYiCE MyXalytics 8.3 High2024-01-03
CVE-2023-50344 Unauthenticated File Downloads affect DRYiCE MyXalytics — DRYiCE MyXalytics 5.4 Medium2024-01-03
CVE-2023-50345 Open Redirect affects DRYiCE MyXalytics — DRYiCE MyXalytics 3.7 Low2024-01-03
CVE-2023-50346 An information disclosure affects DRYiCE MyXalytics — DRYiCE MyXalytics 3.1 Low2024-01-03
CVE-2023-50348 Improper Error Handling affects DRYiCE MyXalytics — DRYiCE MyXalytics 3.1 Low2024-01-03
CVE-2023-50350 A broken cryptographic algorithm impacts MyXalytics — DRYiCE MyXalytics 8.2 High2024-01-03
CVE-2023-50351 Insecure key rotation affects MyXalytics — DRYiCE MyXalytics 8.2 High2024-01-03

This page lists every published CVE security advisory associated with HCL Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.