Show filters
218 Total Results
Displaying 41-50 of 218
Sort by:
Attacker Value
Unknown
CVE-2023-45701
Disclosure Date: December 28, 2023 (last updated January 05, 2024)
HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
0
Attacker Value
Unknown
CVE-2023-37520
Disclosure Date: December 21, 2023 (last updated December 30, 2023)
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.
0
Attacker Value
Unknown
CVE-2023-37519
Disclosure Date: December 21, 2023 (last updated December 30, 2023)
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server.
0
Attacker Value
Unknown
CVE-2023-45700
Disclosure Date: December 21, 2023 (last updated January 03, 2024)
HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2023-28025
Disclosure Date: December 21, 2023 (last updated December 30, 2023)
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.
0
Attacker Value
Unknown
CVE-2023-45703
Disclosure Date: December 21, 2023 (last updated January 03, 2024)
HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion.
0
Attacker Value
Unknown
CVE-2023-28022
Disclosure Date: December 15, 2023 (last updated December 21, 2023)
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
0
Attacker Value
Unknown
CVE-2023-28017
Disclosure Date: December 07, 2023 (last updated December 13, 2023)
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
0
Attacker Value
Unknown
CVE-2023-37533
Disclosure Date: November 09, 2023 (last updated November 17, 2023)
HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow the attacker to steal cookie-based authentication credentials and comprise a user's account then launch other attacks.
0
Attacker Value
Unknown
CVE-2023-37532
Disclosure Date: October 23, 2023 (last updated October 31, 2023)
HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.
0