Show filters
218 Total Results
Displaying 91-100 of 218
Sort by:
Attacker Value
Unknown

CVE-2021-27782

Disclosure Date: January 20, 2023 (last updated November 08, 2023)
HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.
Attacker Value
Unknown

CVE-2022-38658

Disclosure Date: December 24, 2022 (last updated November 08, 2023)
BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data exposed.
Attacker Value
Unknown

CVE-2022-44756

Disclosure Date: December 21, 2022 (last updated November 08, 2023)
Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires privileged access. 
Attacker Value
Unknown

CVE-2022-42454

Disclosure Date: December 21, 2022 (last updated November 08, 2023)
Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure.  This requires privileged network access.
Attacker Value
Unknown

CVE-2022-38655

Disclosure Date: December 21, 2022 (last updated November 08, 2023)
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.
Attacker Value
Unknown

CVE-2022-44755

Disclosure Date: December 19, 2022 (last updated November 08, 2023)
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44751.  This vulnerability applies to software previously licensed by IBM.
Attacker Value
Unknown

CVE-2022-44754

Disclosure Date: December 19, 2022 (last updated November 08, 2023)
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44750.  This vulnerability applies to software previously licensed by IBM.
Attacker Value
Unknown

CVE-2022-44753

Disclosure Date: December 19, 2022 (last updated November 08, 2023)
HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to software previously licensed by IBM.
Attacker Value
Unknown

CVE-2022-44752

Disclosure Date: December 19, 2022 (last updated November 08, 2023)
HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to software previously licensed by IBM.
Attacker Value
Unknown

CVE-2022-44751

Disclosure Date: December 19, 2022 (last updated November 08, 2023)
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755.  This vulnerability applies to software previously licensed by IBM.