Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

HCL Software — Vulnerabilities & Security Advisories 397

Browse all 397 CVE security advisories affecting HCL Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HCL Software specializes in enterprise application development and management tools, primarily serving large organizations with legacy and modernization needs. Its portfolio includes Domino, OpenPages, and various integration platforms, which historically present a diverse attack surface. Common vulnerability classes affecting these products include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configurations or outdated underlying frameworks. The company has addressed numerous security flaws, with records indicating hundreds of disclosed CVEs over the years. Notable incidents have involved authentication bypasses and injection flaws in older versions of its collaboration suites. HCL Software generally responds to these issues through regular patch cycles and security advisories, though the sheer volume of legacy code contributes to the high number of recorded vulnerabilities. Users are advised to maintain strict update protocols to mitigate risks associated with these known security gaps.

CVE ID Title CVSS Severity Published
CVE-2022-27560 An insufficiently protected credential vulnerability affects HCL VersionVault Express — HCL VersionVault Express CWE-522 6.0 Medium 2022-08-30
CVE-2022-27558 HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. — HCL iNotes CWE-521 5.9 Medium 2022-08-29
CVE-2022-27547 HCL iNotes is susceptible to a link to non-existent domain vulnerability. — HCL iNotes CWE-601 6.1 Medium 2022-08-29
CVE-2022-27546 HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability — HCL iNotes CWE-79 8.3 High 2022-08-29
CVE-2022-27551 HCL Launch could allow an authenticated user to obtain sensitive information (CVE-2022-27551) — HCL Launch CWE-863 5.3 Medium 2022-08-03
CVE-2021-27785 HCL Commerce could allow a local attacker to obtain sensitive personal information (CVE-2021-27785) — HCL Commerce CWE-522 3.9 Low 2022-07-29
CVE-2022-27545 HCL BigFix Web Reports authorized users may perform HTML injection. — HCL BigFix CWE-79 4.6 Medium 2022-07-19
CVE-2022-27544 HCL BigFix Web Reports authorized users may see sensitive information in clear text — HCL BigFix CWE-522 5.0 Medium 2022-07-19
CVE-2022-27549 HCL Launch could disclose sensitive database information to a local user in plain text. — HCL Launch CWE-532 4.0 Medium 2022-07-06
CVE-2022-27548 HCL Launch is vulnerable to information disclosure which can be read by a local user. — HCL Launch CWE-256 4.9 Medium 2022-07-06
CVE-2021-27786 HCL OneTest Server is vulnerable to Cross Origin Resource Sharing: Arbitrary Origin Trusted — HCL OneTest Server CWE-942 4.6 Medium 2022-06-07
CVE-2021-27778 HCL Traveler is susceptible to a cross-site scripting vulnerability which could allow an attacker to execute a malicious script to access sensitive information. — HCL Traveler CWE-79 4.9 Medium 2022-05-31
CVE-2021-27781 HCL BigFix Mobile / Modern Client Management is vulnerable to stored cross-site scripting — HCL BigFix Mobile / Modern Client Management CWE-79 6.6 Medium 2022-05-27
CVE-2021-27780 HCL BigFix Mobile / Modern Client Management is vulnerable to unauthenticated XML interaction — HCL BigFix Mobile / Modern Client Management CWE-112 5.3 Medium 2022-05-27
CVE-2021-27783 HCL BigFix Mobile / Modern Client Management is vulnerable to sensitive information exposure — HCL BigFix Mobile / Modern Client Management CWE-311 6.8 Medium 2022-05-25
CVE-2021-27779 A Security Misconfiguration vulnerability affects HCL VersionVault Express — HCL VersionVault Express CWE-311 9.1 Critical 2022-05-25
CVE-2020-4107 HCL Domino is affected by an Insufficient Access Control vulnerability — HCL Domino CWE-284 8.8 High 2022-05-19
CVE-2021-27777 HCL Unica Platform is vulnerable to XML External Entity (XXE) injection — HCL Unica CWE-91 7.5 High 2022-05-12
CVE-2021-27773 HCL Sametime is vulnerable to clickjacking — Sametime CWE-451 4.2 Medium 2022-05-12
CVE-2021-27772 HCL Sametime is vulnerable to an information disclosure — Sametime CWE-285 7.1 High 2022-05-12
CVE-2021-27771 HCL Sametime is susceptible a file transfer service vulnerability — Sametime CWE-434 8.2 High 2022-05-12
CVE-2021-27770 HCL Sametime is vulnerable to arbitrary HTTP requests — Sametime CWE-472 6.8 Medium 2022-05-12
CVE-2021-27769 HCL Sametime is vulnerable to an information disclosure — Sametime CWE-472 5.3 Medium 2022-05-12
CVE-2021-27768 An SSL certificate host verification vulnerability affects HCL Verse for Android — Verse for Android CWE-300 6.3 Medium 2022-05-12
CVE-2021-27767 HCL BigFix Platform Console is affected by a Privilege Escalation Vulnerability — BigFix Platform CWE-269 6.7 Medium 2022-05-06
CVE-2021-27766 HCL BigFix Platform Client is affected by a Privilege Escalation Vulnerability — BigFix Platform CWE-269 6.7 Medium 2022-05-06
CVE-2021-27765 HCL BigFix Platform Server API is affected by Privilege Escalation Vulnerability — BigFix Platform CWE-269 6.7 Medium 2022-05-06
CVE-2021-27764 HCL BigFix WebUI Cookie missing attributes — HCL BigFix WebUI CWE-614 7.4 High 2022-05-06
CVE-2021-27762 HCL BigFix Platform is affected by misconfigured security-related HTTP headers — BigFix Platform 4.7 Medium 2022-05-06
CVE-2021-27761 HCL BigFix Platform is affected by weak web transport security — BigFix Platform 4.8 Medium 2022-05-06

This page lists every published CVE security advisory associated with HCL Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.