Show filters
66 Total Results
Displaying 41-50 of 66
Sort by:
Attacker Value
Unknown

CVE-2024-30112

Disclosure Date: June 25, 2024 (last updated June 26, 2024)
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise user's account then launch other attacks.
0
Attacker Value
Unknown

CVE-2023-37541

Disclosure Date: June 25, 2024 (last updated June 26, 2024)
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
0
Attacker Value
Unknown

CVE-2024-30120

Disclosure Date: June 14, 2024 (last updated June 15, 2024)
HCL DRYiCE Optibot Reset Station is impacted by an Unused Parameter in the web application.
0
Attacker Value
Unknown

CVE-2024-30119

Disclosure Date: June 14, 2024 (last updated June 15, 2024)
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header.  This could allow an attacker to intercept or manipulate data during redirection.
0
Attacker Value
Unknown

CVE-2023-45707

Disclosure Date: June 08, 2024 (last updated June 09, 2024)
HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks.
0
Attacker Value
Unknown

CVE-2024-23580

Disclosure Date: May 28, 2024 (last updated May 29, 2024)
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted values.
0
Attacker Value
Unknown

CVE-2024-23579

Disclosure Date: May 28, 2024 (last updated May 29, 2024)
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover some or all encrypted values.
0
Attacker Value
Unknown

CVE-2024-23556

Disclosure Date: May 18, 2024 (last updated May 18, 2024)
SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.
0
Attacker Value
Unknown

CVE-2024-23554

Disclosure Date: May 18, 2024 (last updated May 18, 2024)
Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).
0
Attacker Value
Unknown

CVE-2024-23583

Disclosure Date: May 17, 2024 (last updated May 18, 2024)
An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.
0