Show filters
218 Total Results
Displaying 111-120 of 218
Sort by:
Attacker Value
Unknown
CVE-2022-38660
Disclosure Date: November 04, 2022 (last updated February 24, 2025)
HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.
0
Attacker Value
Unknown
CVE-2021-27784
Disclosure Date: October 19, 2022 (last updated February 24, 2025)
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.
0
Attacker Value
Unknown
CVE-2020-4099
Disclosure Date: October 14, 2022 (last updated February 24, 2025)
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.
0
Attacker Value
Unknown
CVE-2021-27774
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
User input included in error response, which could be used in a phishing attack.
0
Attacker Value
Unknown
CVE-2022-27561
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).
0
Attacker Value
Unknown
CVE-2022-27560
Disclosure Date: August 26, 2022 (last updated February 24, 2025)
HCL VersionVault Express exposes administrator credentials.
0
Attacker Value
Unknown
CVE-2022-27563
Disclosure Date: August 26, 2022 (last updated February 24, 2025)
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
0
Attacker Value
Unknown
CVE-2022-27558
Disclosure Date: August 24, 2022 (last updated February 24, 2025)
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
0
Attacker Value
Unknown
CVE-2022-27546
Disclosure Date: August 24, 2022 (last updated February 24, 2025)
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.
0
Attacker Value
Unknown
CVE-2022-27547
Disclosure Date: August 24, 2022 (last updated February 24, 2025)
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
0