Show filters
287 Total Results
Displaying 21-30 of 287
Sort by:
Attacker Value
Unknown
CVE-2024-30129
Disclosure Date: December 06, 2024 (last updated December 21, 2024)
The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would cause the request to be sent to a completely different domain/IP address.
0
Attacker Value
Unknown
CVE-2024-42196
Disclosure Date: December 06, 2024 (last updated December 21, 2024)
HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
0
Attacker Value
Unknown
CVE-2024-42195
Disclosure Date: December 05, 2024 (last updated December 21, 2024)
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2024-42188
Disclosure Date: November 14, 2024 (last updated November 15, 2024)
HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.
0
Attacker Value
Unknown
CVE-2024-30133
Disclosure Date: November 12, 2024 (last updated November 13, 2024)
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.
0
Attacker Value
Unknown
CVE-2024-30142
Disclosure Date: November 07, 2024 (last updated November 07, 2024)
HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.
0
Attacker Value
Unknown
CVE-2024-30141
Disclosure Date: November 07, 2024 (last updated November 07, 2024)
HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about its environment, users, or associated data.
0
Attacker Value
Unknown
CVE-2024-30140
Disclosure Date: November 07, 2024 (last updated November 07, 2024)
HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.
0
Attacker Value
Unknown
CVE-2024-30149
Disclosure Date: October 31, 2024 (last updated October 31, 2024)
HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.
0
Attacker Value
Unknown
CVE-2024-30106
Disclosure Date: October 28, 2024 (last updated November 09, 2024)
HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entitled to due to the improper handling of request data.
0