Show filters
218 Total Results
Displaying 121-130 of 218
Sort by:
Attacker Value
Unknown

CVE-2022-27551

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
Attacker Value
Unknown

CVE-2021-27785

Disclosure Date: July 29, 2022 (last updated February 24, 2025)
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.
Attacker Value
Unknown

CVE-2022-27545

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
Attacker Value
Unknown

CVE-2022-27544

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
BigFix Web Reports authorized users may see SMTP credentials in clear text.
Attacker Value
Unknown

CVE-2022-27549

Disclosure Date: July 01, 2022 (last updated February 24, 2025)
HCL Launch may store certain data for recurring activities in a plain text format.
Attacker Value
Unknown

CVE-2022-27548

Disclosure Date: July 01, 2022 (last updated February 24, 2025)
HCL Launch stores user credentials in plain clear text which can be read by a local user.
Attacker Value
Unknown

CVE-2021-27786

Disclosure Date: June 07, 2022 (last updated February 23, 2025)
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.
Attacker Value
Unknown

CVE-2021-27778

Disclosure Date: May 31, 2022 (last updated February 23, 2025)
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.
Attacker Value
Unknown

CVE-2021-27783

Disclosure Date: May 19, 2022 (last updated February 23, 2025)
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
Attacker Value
Unknown

CVE-2021-27780

Disclosure Date: May 09, 2022 (last updated February 23, 2025)
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.