Show filters
218 Total Results
Displaying 191-200 of 218
Sort by:
Attacker Value
Unknown

CVE-2019-4325

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
Attacker Value
Unknown

CVE-2019-4326

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
Attacker Value
Unknown

CVE-2020-14223

Disclosure Date: October 01, 2020 (last updated February 22, 2025)
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.
Attacker Value
Unknown

CVE-2020-4104

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855&sys_kb_id=971d99ed1b8ed01c086dcbfc0a4bcb6a.
Attacker Value
Unknown

CVE-2019-4090

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
"HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."
Attacker Value
Unknown

CVE-2019-4091

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "
Attacker Value
Unknown

CVE-2020-4095

Disclosure Date: July 16, 2020 (last updated February 21, 2025)
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."
Attacker Value
Unknown

CVE-2020-4100

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded natively at runtime; however, dynamically loaded components are only loaded as they are specifically requested. While this can have a positive impact on performance, or grant additional functionality (for example, a non-invasive update feature), it can also open the application to loading unintended code if not implemented properly."
Attacker Value
Unknown

CVE-2019-4324

Disclosure Date: July 07, 2020 (last updated February 21, 2025)
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
Attacker Value
Unknown

CVE-2019-4323

Disclosure Date: July 07, 2020 (last updated February 21, 2025)
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."