Show filters
218 Total Results
Displaying 161-170 of 218
Sort by:
Attacker Value
Unknown

CVE-2020-14246

Disclosure Date: February 04, 2021 (last updated February 22, 2025)
HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials.
Attacker Value
Unknown

CVE-2020-4081

Disclosure Date: February 02, 2021 (last updated February 22, 2025)
In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).
Attacker Value
Unknown

CVE-2020-14221

Disclosure Date: February 02, 2021 (last updated November 28, 2024)
HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.
Attacker Value
Unknown

CVE-2020-14255

Disclosure Date: February 02, 2021 (last updated November 28, 2024)
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditional on-premise installations.
Attacker Value
Unknown

CVE-2020-14275

Disclosure Date: January 12, 2021 (last updated November 28, 2024)
Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
Attacker Value
Unknown

CVE-2020-14274

Disclosure Date: January 12, 2021 (last updated November 28, 2024)
Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.
Attacker Value
Unknown

CVE-2020-14273

Disclosure Date: December 28, 2020 (last updated February 22, 2025)
HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino server.
Attacker Value
Unknown

CVE-2020-14270

Disclosure Date: December 22, 2020 (last updated February 22, 2025)
HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthenticated attacker could exploit this vulnerability to obtain information about the XPages software running on the Domino server.
Attacker Value
Unknown

CVE-2020-14231

Disclosure Date: December 22, 2020 (last updated February 22, 2025)
A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the privileges of the currently logged in user.
Attacker Value
Unknown

CVE-2020-14225

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack.