Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

HCL Software — Vulnerabilities & Security Advisories 397

Browse all 397 CVE security advisories affecting HCL Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HCL Software specializes in enterprise application development and management tools, primarily serving large organizations with legacy and modernization needs. Its portfolio includes Domino, OpenPages, and various integration platforms, which historically present a diverse attack surface. Common vulnerability classes affecting these products include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configurations or outdated underlying frameworks. The company has addressed numerous security flaws, with records indicating hundreds of disclosed CVEs over the years. Notable incidents have involved authentication bypasses and injection flaws in older versions of its collaboration suites. HCL Software generally responds to these issues through regular patch cycles and security advisories, though the sheer volume of legacy code contributes to the high number of recorded vulnerabilities. Users are advised to maintain strict update protocols to mitigate risks associated with these known security gaps.

CVE ID Title CVSS Severity Published
CVE-2025-52619 HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure — BigFix SaaS Remediate CWE-209 5.3 Medium 2025-08-15
CVE-2025-52620 HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability — BigFix SaaS Remediate CWE-20 4.3 Medium 2025-08-15
CVE-2025-52621 HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning — BigFix SaaS Remediate CWE-346 5.3 Medium 2025-08-15
CVE-2025-31961 HCL Connections is vulnerable to broken access control — Connections CWE-1220 3.7 Low 2025-08-15
CVE-2025-31987 HCL Connections Docs is vulnerable to a Denial of Service (DoS) attack — Connections Docs CWE-405 4.8 Medium 2025-08-14
CVE-2025-31965 HCL BigFix Remote Control is affected by an authorization bypass vulnerability — BigFix Remote Control CWE-305 8.2 High 2025-07-29
CVE-2025-0253 HCL IEM is affected by a cookie attribute not set vulnerability — IEM CWE-384 2.0 Low 2025-07-25
CVE-2025-0252 HCL IEM is affected by a password in cleartext vulnerability — IEM CWE-319 2.6 Low 2025-07-25
CVE-2025-0251 HCL IEM is affected by a concurrent login vulnerability — IEM CWE-384 2.6 Low 2025-07-25
CVE-2025-0250 HCL IEM is affected by an authorization token sent in cookie vulnerability — IEM CWE-319 2.2 Low 2025-07-24
CVE-2025-0249 HCL IEM is affected by an improper invalidation of access or JWT token vulnerability — IEM CWE-287 3.3 Low 2025-07-24
CVE-2025-31952 HCL iAutomate is affected by an insufficient session expiration — iAutomate CWE-613 7.1 High 2025-07-24
CVE-2025-31955 HCL iAutomate is affected by a sensitive data exposure vulnerability — iAutomate CWE-200 7.6 High 2025-07-24
CVE-2025-31953 HCL iAutomate is affected by hardcoded credentials — iAutomate CWE-798 7.1 High 2025-07-24
CVE-2024-42209 HCL Connections is vulnerable to an information disclosure vulnerability — Connections CWE-200 3.5 Low 2025-07-17
CVE-2024-42191 HCL Traveler for Microsoft Outlook (HTMO) is susceptible to COM hijacking — HCL Traveler for Microsoft Outlook (HTMO) CWE-427 6.5 Medium 2025-05-30
CVE-2024-42190 HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking — HCL Traveler for Microsoft Outlook (HTMO) CWE-427 6.5 Medium 2025-05-30
CVE-2024-23589 HCL Glovius Cloud is susceptible to an Outdated Hash Algorithm vulnerability — HCL Glovius Cloud CWE-328 6.8 Medium 2025-05-30
CVE-2024-42213 HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment — HCL BigFix Compliance CWE-531 5.3 Medium 2025-05-05
CVE-2024-42212 HCL BigFix Compliance is affected by an improper or missing SameSite attribute — HCL BigFix Compliance CWE-1275 5.4 Medium 2025-05-05
CVE-2024-30146 HCL Domino Leap is affected by improper access control — HCL Domino Leap CWE-284 4.1 Medium 2025-04-30
CVE-2024-30145 HCL Domino Volt and Domino Leap are affected by a cross-site scripting (XSS) vulnerability — HCL Domino Leap CWE-79 6.5 Medium 2025-04-30
CVE-2024-30115 HCL Domino Volt and Domino Leap are affected by a cross-site scripting (XSS) vulnerability — HCL Domino Leap CWE-79 6.3 Medium 2025-04-30
CVE-2023-45721 HCL Domino Volt and Domino Leap are affected by a disclosure of private personal information vulnerability — HCL Domino Leap CWE-359 5.3 Medium 2025-04-30
CVE-2023-37535 HCL Domino Volt and Domino Leap are affected by a Cross-site scripting (XSS) vulnerability — HCL Domino Leap CWE-79 7.1 High 2025-04-30
CVE-2023-37517 HCL Domino Volt and Domino Leap are affected by missing "no cache" headers — HCL Domino Leap CWE-524 3.2 Low 2025-04-30
CVE-2022-42450 HCL Domino Volt is affected by Cross-site scripting (XSS) — HCL Domino Volt CWE-79 4.6 Medium 2025-04-30
CVE-2022-42449 HCL Domino Volt is affected by an unrestricted upload of a dangerous file type — HCL Domino Volt CWE-434 4.6 Medium 2025-04-30
CVE-2022-27562 HCL Domino Volt is affected by an unrestricted upload of a dangerous file type — HCL Domino Volt CWE-434 4.6 Medium 2025-04-30
CVE-2024-30152 HCL SX is affected by usage of a weak cryptographic algorithm — HCL SX CWE-327 6.5 Medium 2025-04-25

This page lists every published CVE security advisory associated with HCL Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.