Show filters
326 Total Results
Displaying 251-260 of 326
Sort by:
Attacker Value
Unknown

CVE-2019-4091

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "
Attacker Value
Unknown

CVE-2020-4095

Disclosure Date: July 16, 2020 (last updated February 21, 2025)
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."
Attacker Value
Unknown

CVE-2019-4324

Disclosure Date: July 07, 2020 (last updated February 21, 2025)
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
Attacker Value
Unknown

CVE-2019-4323

Disclosure Date: July 07, 2020 (last updated February 21, 2025)
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
Attacker Value
Unknown

CVE-2017-1712

Disclosure Date: July 01, 2020 (last updated February 21, 2025)
"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions."
Attacker Value
Unknown

CVE-2020-4089

Disclosure Date: June 26, 2020 (last updated November 28, 2024)
HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and 11 are affected.
Attacker Value
Unknown

CVE-2020-4101

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
"HCL Digital Experience is susceptible to Server Side Request Forgery."
Attacker Value
Unknown

CVE-2020-12860

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can have four roles and COVIDSafe uses all of them. This allows for re-identification of a device, and potentially identification of the owner's name.
Attacker Value
Unknown

CVE-2020-12859

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify a device model by observing cleartext payload data. This allows re-identification of devices, especially less common phone models or those in low-density situations.
Attacker Value
Unknown

CVE-2020-12857

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
Caching of GATT characteristic values (TempID) in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to long-term re-identify an Android device running COVIDSafe.