Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

HCLSoftware — Vulnerabilities & Security Advisories 95

Browse all 95 CVE security advisories affecting HCLSoftware. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HCLSoftware develops enterprise software solutions including application development, integration, and digital experience platforms. Historically, their products have been vulnerable to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and access control flaws. With 19 CVEs currently on record, security researchers have identified consistent patterns in their codebase. While no major public security incidents have been widely documented, the volume of disclosed vulnerabilities suggests ongoing challenges in secure coding practices. Organizations implementing HCLSoftware solutions should prioritize regular patching and hardening of these environments to mitigate potential exploitation risks.

CVE ID Title CVSS Severity Published
CVE-2026-56587 HCL IEM was affected with Strict transport security not enforced — IntelliOps Event Management CWE-523 3.7 Low 2026-07-21
CVE-2026-56584 HCL IEM was affected with the Information disclosure nginx server — IntelliOps Event Management CWE-200 3.7 Low 2026-07-21
CVE-2023-37507 An information disclosure vulnerability affects HCL DevOps Plan — DevOps Plan CWE-497 - - 2026-07-21
CVE-2023-37508 HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerability — DevOps Plan CWE-79 - - 2026-07-21
CVE-2026-21824 A privilege escalation vulnerability affects HCL Commerce — Commerce CWE-266 8.8 High 2026-07-20
CVE-2025-59866 HCLSoftware DFMPro for CATIA 权限许可和访问控制问题漏洞 — DFMPro for CATIA CWE-732 3.3 Low 2026-07-17
CVE-2026-21764 Insufficient Input Validation in DevOps Loop — DevOps Loop CWE-754 3.1 Low 2026-07-17
CVE-2026-21762 Missing HTTP Security Headers in DevOps Loop — DevOps Loop CWE-644 3.7 Low 2026-07-17
CVE-2026-21761 CORS Misconfiguration in DevOps Loop — DevOps Loop CWE-942 4.2 Medium 2026-07-17
CVE-2026-21760 Unauthorized Access to Admin Functionality via Forced Browsing — DevOps Loop CWE-425 4.6 Medium 2026-07-17
CVE-2024-23572 HCL Aftermarket EPC 会话机制问题漏洞 — Aftermarket EPC CWE-614 4.2 Medium 2026-07-17
CVE-2024-23570 HCL Aftermarket EPC 信息泄露漏洞 — Aftermarket EPC CWE-200 4.3 Medium 2026-07-17
CVE-2024-23578 HCL Aftermarket EPC 配置错误漏洞 — Aftermarket EPC CWE-942 4.2 Medium 2026-07-17
CVE-2024-23569 HCL Aftermarket EPC 跨站脚本漏洞 — Aftermarket EPC CWE-692 4.3 Medium 2026-07-17
CVE-2024-23577 HCL Aftermarket EPC 输入验证错误漏洞 — Aftermarket EPC CWE-20 4.3 Medium 2026-07-17
CVE-2024-23574 HCL Aftermarket EPC 侧信道信息泄露漏洞 — Aftermarket EPC CWE-204 5.3 Medium 2026-07-17
CVE-2024-42214 HCL Aftermarket EPC 跨站脚本漏洞 — Aftermarket EPC CWE-692 5.3 Medium 2026-07-17
CVE-2024-23575 HCL Aftermarket EPC 信息泄露漏洞 — Aftermarket EPC CWE-209 5.3 Medium 2026-07-17
CVE-2024-23571 HCL Aftermarket EPC 信息泄露漏洞 — Aftermarket EPC CWE-525 4.3 Medium 2026-07-17
CVE-2024-23573 HCL Aftermarket EPC 授权问题漏洞 — Aftermarket EPC CWE-425 3.7 Low 2026-07-17
CVE-2024-23568 HCL Aftermarket EPC 信息泄露漏洞 — Aftermarket EPC CWE-200 5.3 Medium 2026-07-17
CVE-2024-23565 HCL Aftermarket EPC 资源管理错误漏洞 — Aftermarket EPC CWE-799 5.3 Medium 2026-07-17
CVE-2024-23566 HCL Aftermarket EPC 授权问题漏洞 — Aftermarket EPC CWE-804 6.5 Medium 2026-07-17
CVE-2024-23567 HCL Aftermarket EPC 授权问题漏洞 — Aftermarket EPC CWE-804 4.3 Medium 2026-07-17
CVE-2026-21770 HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking — HCL Traveler for Microsoft Outlook (HTMO) CWE-427 6.5 Medium 2026-07-17
CVE-2026-35146 HCL DFXServer is affected by an Unencrypted Communication vulnerability. — DFXServer CWE-326 6.3 Medium 2026-07-16
CVE-2026-21840 HCL BigFix Platform is affected by a user enumeration vulnerability — HCL BigFix Platform CWE-208 3.1 Low 2026-07-14
CVE-2026-56460 HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerability — HCL DevOps Deploy / HCL Launch CWE-201 6.5 Medium 2026-07-09
CVE-2026-56458 HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains — HCL DevOps Deploy CWE-942 5.4 Medium 2026-07-09
CVE-2026-56459 HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure — HCL DevOps Deploy / HCL Launch CWE-532 6.2 Medium 2026-07-09

This page lists every published CVE security advisory associated with HCLSoftware. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.