Browse all 397 CVE security advisories affecting HCL Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.
HCL Software specializes in enterprise application development and management tools, primarily serving large organizations with legacy and modernization needs. Its portfolio includes Domino, OpenPages, and various integration platforms, which historically present a diverse attack surface. Common vulnerability classes affecting these products include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configurations or outdated underlying frameworks. The company has addressed numerous security flaws, with records indicating hundreds of disclosed CVEs over the years. Notable incidents have involved authentication bypasses and injection flaws in older versions of its collaboration suites. HCL Software generally responds to these issues through regular patch cycles and security advisories, though the sheer volume of legacy code contributes to the high number of recorded vulnerabilities. Users are advised to maintain strict update protocols to mitigate risks associated with these known security gaps.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2021-27760 | HCL Notes 11.0 - 11.0.1 FP4 Sametime Embedded chat clients are vulnerable to group chats loading script on restart — HCL Notes CWE-20 | 4.6 | Medium | 2022-05-06 |
| CVE-2021-27759 | HCL Technologies BigFix Platform 数据伪造问题漏洞 — HCL BigFix Inventory CWE-352 | 2.3 | Low | 2022-05-06 |
| CVE-2021-27758 | HCL BigFix Platform 跨站请求伪造漏洞 — HCL BigFix Inventory CWE-352 | 4.3 | Medium | 2022-05-06 |
| CVE-2021-27751 | HCL Commerce is affected by an Insufficient Session Expiration vulnerability. — HCL Commerce CWE-613 | 4.4 | Medium | 2022-05-06 |
| CVE-2020-4084 | HCL Technologies Connections 跨站脚本漏洞 — HCL Connections | 5.4 | - | 2020-03-09 |
| CVE-2020-4082 | HCL Technologies Connections 跨站脚本漏洞 — "HCL Connections" | 5.4 | - | 2020-03-05 |
| CVE-2020-4083 | HCL Technologies Connections 日志信息泄露漏洞 — "HCL Connections" | 5.5 | - | 2020-03-05 |
This page lists every published CVE security advisory associated with HCL Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.