Show filters
218 Total Results
Displaying 51-60 of 218
Sort by:
Attacker Value
Unknown

CVE-2023-37503

Disclosure Date: October 19, 2023 (last updated October 25, 2023)
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
Attacker Value
Unknown

CVE-2023-37504

Disclosure Date: October 19, 2023 (last updated October 25, 2023)
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user.
Attacker Value
Unknown

CVE-2023-37502

Disclosure Date: October 18, 2023 (last updated October 25, 2023)
HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that can be executed by the server or by a user's web browser.
Attacker Value
Unknown

CVE-2023-37537

Disclosure Date: October 17, 2023 (last updated October 25, 2023)
An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.
Attacker Value
Unknown

CVE-2023-37538

Disclosure Date: October 11, 2023 (last updated October 19, 2023)
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
Attacker Value
Unknown

CVE-2023-37536

Disclosure Date: October 11, 2023 (last updated November 16, 2023)
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
Attacker Value
Unknown

CVE-2022-44758

Disclosure Date: October 11, 2023 (last updated October 24, 2023)
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.
Attacker Value
Unknown

CVE-2022-44757

Disclosure Date: October 11, 2023 (last updated October 24, 2023)
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.
Attacker Value
Unknown

CVE-2022-42451

Disclosure Date: October 11, 2023 (last updated October 24, 2023)
Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.
Attacker Value
Unknown

CVE-2023-28010

Disclosure Date: September 08, 2023 (last updated October 08, 2023)
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks.