HCL iControl是印度HCL公司的一个IT基础设施监控与自动化运维平台。 HCL iControl 4.0.0版本存在安全漏洞,该漏洞源于未处理异常导致堆栈跟踪泄露,由于访问未定义对象的dashboard键属性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-59874 | 8.1 HIGH | HCL Hive Telco Observability is affected by a Required directives missing from the CSP . |
| CVE-2025-52612 | 7.1 HIGH | HCL iControl was affected by Export CSV - CSV Injection vulnerability. |
| CVE-2025-52606 | 4.3 MEDIUM | HCL iControl was affected by Weak Input Validation vulnerability. . |
| CVE-2025-52609 | 3.7 LOW | HCL iControl was affected by Missing Security Headers vulnerability. |
| CVE-2025-52608 | 3.1 LOW | HCL iControl was affected by Missing Cookie Attributes vulnerability. |
No comments yet