Show filters
218 Total Results
Displaying 121-130 of 218
Sort by:
Attacker Value
Unknown
CVE-2022-27551
Disclosure Date: August 01, 2022 (last updated February 24, 2025)
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
0
Attacker Value
Unknown
CVE-2021-27785
Disclosure Date: July 29, 2022 (last updated February 24, 2025)
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.
0
Attacker Value
Unknown
CVE-2022-27545
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
0
Attacker Value
Unknown
CVE-2022-27544
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
BigFix Web Reports authorized users may see SMTP credentials in clear text.
0
Attacker Value
Unknown
CVE-2022-27549
Disclosure Date: July 01, 2022 (last updated February 24, 2025)
HCL Launch may store certain data for recurring activities in a plain text format.
0
Attacker Value
Unknown
CVE-2022-27548
Disclosure Date: July 01, 2022 (last updated February 24, 2025)
HCL Launch stores user credentials in plain clear text which can be read by a local user.
0
Attacker Value
Unknown
CVE-2021-27786
Disclosure Date: June 07, 2022 (last updated February 23, 2025)
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.
0
Attacker Value
Unknown
CVE-2021-27778
Disclosure Date: May 31, 2022 (last updated February 23, 2025)
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.
0
Attacker Value
Unknown
CVE-2021-27783
Disclosure Date: May 19, 2022 (last updated February 23, 2025)
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
0
Attacker Value
Unknown
CVE-2021-27780
Disclosure Date: May 09, 2022 (last updated February 23, 2025)
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
0