Show filters
218 Total Results
Displaying 81-90 of 218
Sort by:
Attacker Value
Unknown
CVE-2023-23344
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
0
Attacker Value
Unknown
CVE-2023-28016
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause the OSD Bare Metal Server to perform a redirect to an attacker-controlled domain.
0
Attacker Value
Unknown
CVE-2023-28006
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.
0
Attacker Value
Unknown
CVE-2023-23343
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain.
0
Attacker Value
Unknown
CVE-2023-28009
Disclosure Date: April 26, 2023 (last updated October 08, 2023)
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
0
Attacker Value
Unknown
CVE-2023-28008
Disclosure Date: April 26, 2023 (last updated October 08, 2023)
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
0
Attacker Value
Unknown
CVE-2022-42452
Disclosure Date: April 02, 2023 (last updated November 08, 2023)
HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
0
Attacker Value
Unknown
CVE-2022-42447
Disclosure Date: April 02, 2023 (last updated November 08, 2023)
HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.
0
Attacker Value
Unknown
CVE-2021-27788
Disclosure Date: March 10, 2023 (last updated November 08, 2023)
HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability. By tricking a user into clicking a crafted URL, a remote unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
0
Attacker Value
Unknown
CVE-2022-38657
Disclosure Date: February 12, 2023 (last updated November 08, 2023)
An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.
0