Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

HCL Software — Vulnerabilities & Security Advisories 397

Browse all 397 CVE security advisories affecting HCL Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HCL Software specializes in enterprise application development and management tools, primarily serving large organizations with legacy and modernization needs. Its portfolio includes Domino, OpenPages, and various integration platforms, which historically present a diverse attack surface. Common vulnerability classes affecting these products include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configurations or outdated underlying frameworks. The company has addressed numerous security flaws, with records indicating hundreds of disclosed CVEs over the years. Notable incidents have involved authentication bypasses and injection flaws in older versions of its collaboration suites. HCL Software generally responds to these issues through regular patch cycles and security advisories, though the sheer volume of legacy code contributes to the high number of recorded vulnerabilities. Users are advised to maintain strict update protocols to mitigate risks associated with these known security gaps.

CVE ID Title CVSS Severity Published
CVE-2026-35140 HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability — DFXAnalytics CWE-200 3.0 Low 2026-07-16
CVE-2026-35147 HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. — DFXServer CWE-639 8.2 High 2026-07-16
CVE-2026-35149 HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. — DFXServer CWE-294 8.2 High 2026-07-16
CVE-2026-35148 HCL DFXServer is affected by a Missing Access Control vulnerability — DFXServer CWE-284 6.3 Medium 2026-07-16
CVE-2026-9007 Reflected XSS in HCL Notes — HCL Notes CWE-79 - - 2026-07-15
CVE-2025-59872 HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, — ZIE CWE-209 4.3 Medium 2026-06-17
CVE-2025-62340 HCL iControl was affected by Inadequate Session Timeout vulnerability — iControl CWE-613 3.1 Low 2026-06-17
CVE-2025-31974 HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only — BigFix Service Management (SM) CWE-1188 3.9 Low 2026-05-06
CVE-2025-31976 HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials — BigFix Service Management (SM) CWE-200 4.8 Medium 2026-05-06
CVE-2025-31978 HCL BigFix Service Management (SM) does not adequately sanitize or safely render — BigFix Service Management (SM) CWE-201 4.6 Medium 2026-05-06
CVE-2025-31959 HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. — BigFix Service Management (SM) CWE-1230 3.5 Low 2026-05-06
CVE-2025-31982 HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directl — BigFix Service Management (SM) CWE-200 3.7 Low 2026-05-06
CVE-2025-31957 HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. — BigFix Service Management (SM) CWE-352 2.6 Low 2026-05-06
CVE-2025-59873 Session Token Exposure via URL Query Parameters — ZIE for Web 5.9 Medium 2026-02-23
CVE-2025-55252 HCL AION is affected by a Weak Password Policy vulnerability — AION CWE-521 3.1 Low 2026-01-19
CVE-2025-55250 HCL AION is affected by a Technical Error Disclosure vulnerability — AION CWE-209 1.8 Low 2026-01-19
CVE-2025-52661 HCL AION 安全漏洞 — AION CWE-613 2.4 Low 2026-01-19
CVE-2025-55249 HCL AION is affected by a Missing Security Response Headers vulnerability. — AION CWE-693 3.5 Low 2026-01-19
CVE-2025-52659 HCL AION is affected by a Cacheable HTTP Response vulnerability — AION CWE-525 2.8 Low 2026-01-19
CVE-2025-52660 HCL AION is affected by an Host Header Injection vulnerability — AION CWE-644 2.7 Low 2026-01-19
CVE-2025-55251 HCL AION is affected by an Unrestricted File Upload vulnerability — AION CWE-434 3.1 Low 2026-01-19
CVE-2025-59870 Improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk — MyXalytics 7.4 High 2026-01-16
CVE-2025-55254 HCL BigFix Remote Control is vulnerable to a Path-relative stylesheet import (PRSSI) — BigFix Remote Control CWE-601 3.7 Low 2025-12-17
CVE-2025-59849 HCL BigFix Remote Control is vulnerable to an insecure CSP configuration — BigFix Remote Control CWE-1021 4.7 Medium 2025-12-17
CVE-2025-62329 HCL DevOps Deploy / HCL Launch is susceptible to an insufficient session expiration vulnerability — DevOps Deploy / Launch CWE-613 5.0 Medium 2025-12-16
CVE-2025-62330 HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information — DevOps Deploy CWE-319 5.9 Medium 2025-12-16
CVE-2024-42197 HCL Workload Scheduler is vulnerable to plain text storage of a password — Workload Scheduler CWE-256 5.5 Medium 2025-12-11
CVE-2025-52622 HCL BigFix SaaS Remediate is affected by a security vulnerability — BigFix SaaS Remediate CWE-1188 5.4 Medium 2025-12-02
CVE-2025-0248 HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability, — iNotes CWE-20 8.1 High 2025-11-25
CVE-2025-62346 HCL Glovius Cloud is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability — Glovius Cloud CWE-352 6.8 Medium 2025-11-20

This page lists every published CVE security advisory associated with HCL Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.