HCL MyCloud是印度HCL公司的一款云管理软件。 HCL MyCloud 10.8.2版本存在会话机制问题漏洞,该漏洞源于Cookie属性路径未设置,可能增加未经授权访问会话数据或身份验证令牌的风险。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCLSoftware | MyCloud | 10.8.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCLSoftware | MyCloud | 10.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56587 | 3.7 LOW | HCL IEM was affected with Strict transport security not enforced |
| CVE-2026-56584 | 3.7 LOW | HCL IEM was affected with the Information disclosure nginx server |
| CVE-2026-56586 | 3.1 LOW | HCL IEM was affected with X-Content-Type-Options Header Missing |
| CVE-2026-56585 | 3.1 LOW | HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing |
| CVE-2026-56577 | 3.1 LOW | HCL MyCloud affected by Weak Password Policy |
| CVE-2026-56579 | 3.1 LOW | HCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor. |
| CVE-2026-56583 | 3.1 LOW | HCL MyCloud was affected with Concurrent Login Vulnerability. |
| CVE-2026-56582 | 3.1 LOW | HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability. |
| CVE-2026-56578 | 2.2 LOW | HCL MyCloud was affected by Server Version Disclosure |
| CVE-2026-56580 | 2.2 LOW | HCL MyCloud was affected by Using Components with Known Vulnerability |
| CVE-2023-37508 | HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerability | |
| CVE-2023-37507 | An information disclosure vulnerability affects HCL DevOps Plan |
No comments yet