Show filters
218 Total Results
Displaying 71-80 of 218
Sort by:
Attacker Value
Unknown

CVE-2023-37497

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service.
Attacker Value
Unknown

CVE-2023-37496

Disclosure Date: August 01, 2023 (last updated October 08, 2023)
HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
Attacker Value
Unknown

CVE-2023-28014

Disclosure Date: July 27, 2023 (last updated October 08, 2023)
HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.
Attacker Value
Unknown

CVE-2023-28012

Disclosure Date: July 27, 2023 (last updated October 08, 2023)
HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.
Attacker Value
Unknown

CVE-2023-28013

Disclosure Date: July 26, 2023 (last updated October 08, 2023)
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
Attacker Value
Unknown

CVE-2023-28023

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 
Attacker Value
Unknown

CVE-2023-28021

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
The BigFix WebUI uses weak cipher suites.
Attacker Value
Unknown

CVE-2023-28020

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
 URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
Attacker Value
Unknown

CVE-2023-28019

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.
Attacker Value
Unknown

CVE-2023-23348

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.