Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

HCL Software — Vulnerabilities & Security Advisories 397

Browse all 397 CVE security advisories affecting HCL Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HCL Software specializes in enterprise application development and management tools, primarily serving large organizations with legacy and modernization needs. Its portfolio includes Domino, OpenPages, and various integration platforms, which historically present a diverse attack surface. Common vulnerability classes affecting these products include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configurations or outdated underlying frameworks. The company has addressed numerous security flaws, with records indicating hundreds of disclosed CVEs over the years. Notable incidents have involved authentication bypasses and injection flaws in older versions of its collaboration suites. HCL Software generally responds to these issues through regular patch cycles and security advisories, though the sheer volume of legacy code contributes to the high number of recorded vulnerabilities. Users are advised to maintain strict update protocols to mitigate risks associated with these known security gaps.

CVE ID Title CVSS Severity Published
CVE-2024-30124 HCL Sametime is impacted by insecure services — Sametime 4.0 Medium 2024-10-23
CVE-2024-30122 HCL Sametime is impacted by misconfigured security related HTTP headers — Sametime 5.8 Medium 2024-10-23
CVE-2024-30117 HCL BigFix Platform is affected by a DLL Hijack vulnerability — BigFix Platform CWE-427 2.5 Low 2024-10-14
CVE-2024-30118 HCL Connections is susceptible to a sensitive information disclosure vulnerability — Connections CWE-200 3.5 Low 2024-10-09
CVE-2024-30132 Missing default HTTP security headers affect HCL Nomad server on Domino — Nomad server on Domino 3.7 Low 2024-10-01
CVE-2024-23586 An insufficient session timeout vulnerability affects HCL Nomad server on Domino — Nomad server on Domino CWE-613 5.3 Medium 2024-09-27
CVE-2024-30134 HCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerability — HCL Traveler for Microsoft Outlook 6.7 Medium 2024-09-26
CVE-2024-30128 An open proxy vulnerability affects HCL Nomad server on Domino — Nomad server on Domino 8.6 High 2024-09-25
CVE-2024-30130 HCL Nomad server on Domino is affected by a use of web browser cache containing sensitive information vulnerability — Nomad server on Domino CWE-525 3.7 Low 2024-07-19
CVE-2024-30126 HCL BigFix Compliance is affected by a missing X-Frame-Options Header vulnerability — BigFix Compliance 4.7 Medium 2024-07-18
CVE-2024-30125 HCL BigFix Compliance is affected by an internal server error — BigFix Compliance 6.2 Medium 2024-07-18
CVE-2024-23562 HCL Domino is susceptible to an information disclosure vulnerability — Domino Server 5.3 Medium 2024-07-08
CVE-2024-23588 A denial of service vulnerability affects HCL Nomad server on Domino — Nomad server on Domino 5.3 Medium 2024-07-05
CVE-2024-30135 Sensitive Information Disclosure vulnerability affects DRYiCE AEX v10 — DRYiCE AEX CWE-200 3.3 Low 2024-06-28
CVE-2024-30111 Missing Root Detection vulnerability affects DRYiCE AEX v10 — DRYiCE AEX CWE-1326 3.3 Low 2024-06-28
CVE-2024-30110 Lack of input validation vulnerability affects DRYiCE AEX v10 — DRYiCE AEX CWE-20 3.7 Low 2024-06-28
CVE-2024-30109 Lack of Clickjacking Protection vulnerability affects DRYiCE AEX v10 — DRYiCE AEX CWE-1021 3.7 Low 2024-06-28
CVE-2024-30112 HCL Connections is vulnerable to a cross-site scripting (XSS) vulnerability — Connections 5.4 Medium 2024-06-25
CVE-2023-37541 HCL Connections is vulnerable to broken access control — Connections 3.5 Low 2024-06-25
CVE-2024-30120 HCL DRYiCE Optibot Reset Station is impacted by an Unused Parameter in the web application — DRYiCE Optibot Reset Station CWE-563 2.9 Low 2024-06-14
CVE-2024-30119 HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header — DRYiCE Optibot Reset Station CWE-522 3.7 Low 2024-06-14
CVE-2023-45707 HCL Connections Docs is vulnerable to Cross-Site Scripting (XSS) — Connections Docs 4.4 Medium 2024-06-08
CVE-2023-37539 HCL Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability — Domino Server 8.4 High 2024-06-06
CVE-2024-23580 HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs) — DRYiCE Optibot Reset Station 6.5 Medium 2024-05-28
CVE-2024-23579 HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions — DRYiCE Optibot Reset Station 6.5 Medium 2024-05-28
CVE-2024-23556 HCL BigFix Platform is impacted by a failure to restrict SSL/TLS renegotiation — BigFix Platform 5.9 Medium 2024-05-17
CVE-2024-23554 HCL BigFix Platform is susceptible to Cross-Site Request Forgery — BigFix Platform CWE-352 5.7 Medium 2024-05-17
CVE-2024-23583 HCL BigFix Platform is susceptible to insufficiently protected credentials — BigFix Platform CWE-522 6.7 Medium 2024-05-17
CVE-2024-23576 HCL Commerce is potentially affected by a denial of service and information disclosure vulnerability — Commerce 7.1 High 2024-05-13
CVE-2023-37526 HCL DRYiCE Lucy v9 (now AEX) is affected by a Cross Origin Resource Sharing (CORS) Vulnerability — DRYiCE Lucy 6.5 Medium 2024-05-10

This page lists every published CVE security advisory associated with HCL Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.