HCL MyCloud是印度HCL公司的一款云管理软件。 HCL MyCloud 10.8.2版本存在授权问题漏洞,该漏洞源于弱密码策略,可能增加通过暴力破解或基于凭证攻击而破解账户的风险。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCLSoftware | MyCloud | 10.8.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCLSoftware | MyCloud | 10.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56587 | 3.7 LOW | HCL IEM was affected with Strict transport security not enforced |
| CVE-2026-56584 | 3.7 LOW | HCL IEM was affected with the Information disclosure nginx server |
| CVE-2026-56586 | 3.1 LOW | HCL IEM was affected with X-Content-Type-Options Header Missing |
| CVE-2026-56585 | 3.1 LOW | HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing |
| CVE-2026-56579 | 3.1 LOW | HCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor. |
| CVE-2026-56583 | 3.1 LOW | HCL MyCloud was affected with Concurrent Login Vulnerability. |
| CVE-2026-56582 | 3.1 LOW | HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability. |
| CVE-2026-56581 | 2.6 LOW | HCL MyCloud was affected with Cookie Attribute Path Not Set |
| CVE-2026-56578 | 2.2 LOW | HCL MyCloud was affected by Server Version Disclosure |
| CVE-2026-56580 | 2.2 LOW | HCL MyCloud was affected by Using Components with Known Vulnerability |
| CVE-2023-37508 | HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerability | |
| CVE-2023-37507 | An information disclosure vulnerability affects HCL DevOps Plan |
No comments yet