Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

HCL Software — Vulnerabilities & Security Advisories 397

Browse all 397 CVE security advisories affecting HCL Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HCL Software specializes in enterprise application development and management tools, primarily serving large organizations with legacy and modernization needs. Its portfolio includes Domino, OpenPages, and various integration platforms, which historically present a diverse attack surface. Common vulnerability classes affecting these products include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configurations or outdated underlying frameworks. The company has addressed numerous security flaws, with records indicating hundreds of disclosed CVEs over the years. Notable incidents have involved authentication bypasses and injection flaws in older versions of its collaboration suites. HCL Software generally responds to these issues through regular patch cycles and security advisories, though the sheer volume of legacy code contributes to the high number of recorded vulnerabilities. Users are advised to maintain strict update protocols to mitigate risks associated with these known security gaps.

CVE ID Title CVSS Severity Published
CVE-2025-52639 HCL Connections is vulnerable to sensitive information disclosure — Connections CWE-201 3.5 Low 2025-11-18
CVE-2025-55278 HCL DevOps Loop is susceptible to an improper authentication vulnerability — DevOps Loop CWE-613 8.1 High 2025-11-05
CVE-2025-31954 HCL iAutomate is susceptible to a sensitive information disclosure — iAutomate CWE-598 5.4 Medium 2025-11-05
CVE-2025-52602 HCL BigFix Query is affected by a sensitive information disclosure vulnerability in the WebUI Query application — BigFix Query CWE-359 4.2 Medium 2025-11-05
CVE-2024-42192 HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage — Traveler for Microsoft Outlook CWE-522 5.5 Medium 2025-10-16
CVE-2025-0277 HCL BigFix Mobile is affected by an insecure Content Security Policy (CSP) — BigFix Mobile CWE-693 6.5 Medium 2025-10-16
CVE-2025-0276 HCL BigFix Modern Client Management (MCM) is affected by an insecure Content Security Policy (CSP) — BigFix Modern Client Management CWE-693 6.5 Medium 2025-10-16
CVE-2025-0275 HCL BigFix Mobile 3.3 and earlier is affected by improper access control — BigFix Mobile CWE-306 5.3 Medium 2025-10-16
CVE-2025-0274 HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control — BigFix Modern Client Management CWE-306 5.3 Medium 2025-10-16
CVE-2025-31995 HCL Unica MaxAI Workbench is vulnerable to improper input validation — MaxAI Workbench CWE-20 3.5 Low 2025-10-13
CVE-2025-31994 HCL Unica Campaign is vulnerable to Reflected Cross-Site Scripting (XSS) — Unica Campaign CWE-79 4.3 Medium 2025-10-13
CVE-2025-31996 Unprotected files are impacting HCL Unica Platform — Unica Platform CWE-552 5.3 Medium 2025-10-13
CVE-2025-52615 HCL Unica Platform is impacted by misconfigured security related HTTP headers — Unica Platform CWE-693 3.5 Low 2025-10-12
CVE-2025-52614 HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability — Unica Platform CWE-614 3.5 Low 2025-10-12
CVE-2025-31969 HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP) — Unica Platform CWE-358 4.0 Medium 2025-10-12
CVE-2025-31992 HCL MaxAI Assistant is susceptible to a HTML injection vulnerability — MaxAI Assistant CWE-80 4.6 Medium 2025-10-12
CVE-2025-52616 HCL Unica 12.1.10 is affected by an exposure of sensitive information — Unica CWE-497 5.3 Medium 2025-10-12
CVE-2025-31998 HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information — Unica Centralized Offer Management CWE-703 3.5 Low 2025-10-12
CVE-2025-31997 HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR) — Unica Centralized Offer Management CWE-639 4.2 Medium 2025-10-12
CVE-2025-31993 HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF) — Unica Centralized Offer Management CWE-918 3.5 Low 2025-10-12
CVE-2025-52647 HCL BigFix WebUI is affected by a host header poisoning vulnerability — BigFix WebUI CWE-644 6.1 Medium 2025-10-10
CVE-2025-52658 HCL MyXalytics is affected by the use of vulnerable/outdated versions — MyXalytics CWE-1104 3.5 Low 2025-10-03
CVE-2025-52654 HCL MyXalytics is affected by an HTML Injection — HCL MyXalytics CWE-80 4.6 Medium 2025-10-03
CVE-2025-0280 HCL Compass is affected by a security vulnerability — Compass CWE-257 7.5 High 2025-09-03
CVE-2025-31971 AIML Solutions for HCL SX is susceptible to a URL validation vulnerability — AIML Solutions for SX CWE-425 5.1 Medium 2025-08-28
CVE-2025-31979 A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix Service Management (SM) — BigFix Service Management (SM) CWE-434 5.4 Medium 2025-08-28
CVE-2025-31977 A cryptographic weakness has been identified in the HCL BigFix Service Management (SM) — BigFix Service Management (SM) CWE-311 5.3 Medium 2025-08-28
CVE-2025-31972 HCL BigFix Service Management (SM) is affected by a Sensitive Information Exposure vulnerability — BigFix Service Management (SM) CWE-319 6.5 Medium 2025-08-28
CVE-2025-31988 HCL Digital Experience is susceptible to cross site scripting (XSS) — Digital Experience CWE-79 4.9 Medium 2025-08-19
CVE-2025-52618 HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability — BigFix SaaS Remediate CWE-89 4.3 Medium 2025-08-15

This page lists every published CVE security advisory associated with HCL Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.