HCL Connections 存在服务器端请求伪造(SSRF)漏洞:当内部服务器被攻破时,攻击者可能利用此漏洞在特定场景下发送未授权的请求,从而导致信息泄露或绕过安全机制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCLSoftware | Connections | 7.0, 8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-21810 | 4.4 MEDIUM | HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference an |
| CVE-2026-21808 | 4.1 MEDIUM | HCL BigFix Quantum Risk Analyzer is affected by logging sensitive information |
| CVE-2026-21809 | 3.9 LOW | HCL BigFix Quantum Risk Analyzer is affected by generating error messages with sensitive i |
| CVE-2026-21807 | 3.9 LOW | HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflow |
| CVE-2026-56547 | 3.5 LOW | An input reflection vulnerability affects HCL Traveler |
No comments yet