目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

HCLSoftware 厂商漏洞列表 / CVE 中文分析 79

HCLSoftware 厂商相关 79 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

HCLSoftware 提供企业级软件解决方案,涵盖云计算、协作和数字体验等领域。历史漏洞记录显示常见问题包括远程代码执行、跨站脚本请求伪造和权限绕过等。其产品曾因身份验证机制缺陷和配置不当导致多个高危漏洞,影响广泛。安全团队需重点关注其组件更新和权限管理,以防范潜在攻击。

CVE IDタイトルCVSS深刻度公開日
CVE-2025-31981 HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption — BigFix Service Management (SM)CWE-319 5.3 Medium2026-04-21
CVE-2025-31958 HCL BigFix Service Management (SM) is susceptible to HTTP Request Smuggling — BigFix Service Management (SM)CWE-444 3.7 Low2026-04-21
CVE-2025-31991 HCL DevOps Velocity is susceptible to brute-force attacks — VelocityCWE-307 6.8 Medium2026-04-13
CVE-2026-21767 HCL BigFix Platform is affected by insufficient authentication — BigFix PlatformCWE-306 4.0 Medium2026-04-01
CVE-2026-21765 HCL BigFix Platform is affected by insecure permissions on private cryptographic keys — BigFix PlatformCWE-732 8.8 High2026-04-01
CVE-2026-21790 HCL Traveler is susceptible to a weak default HTTP header validation vulnerability — TravelerCWE-346 6.3 Medium2026-03-24
CVE-2026-21783 HCL Traveler is affected by sensitive information disclosure — TravelerCWE-209 4.3 Medium2026-03-24
CVE-2026-21788 HCL Connections is vulnerable to cross-site scripting (XSS) — ConnectionsCWE-79 5.4 Medium2026-03-19
CVE-2024-42210 HCL Unica Marketing Operations v12.1.8 and lower is affected by a Stored cross-site scripting (XSS) vulnerability — Unica Marketing Operations (Plan)CWE-79 7.6 High2026-03-19
CVE-2025-62328 HCL Nomad server on Domino is affected by a missing default frame-ancestors directive — Nomad server on DominoCWE-1021 3.7 Low2026-03-11
CVE-2026-21786 HCL Sametime for iOS is affected by sensitive information disclosure — Sametime for iOSCWE-532 3.3 Low2026-03-05
CVE-2025-62326 HCL Digital Experience is susceptible to stored cross-site scripting (XSS) — Digital ExperienceCWE-79 6.1 Medium2026-02-20
CVE-2025-52603 HCL Connections is vulnerable to information disclosure — ConnectionsCWE-213 3.5 Low2026-02-20
CVE-2025-31990 HCL DevOps Velocity is susceptible to a Denial of Service vulnerability — HCL DevOps VelocityCWE-770 6.8 Medium2026-02-07
CVE-2023-37525 HCL BigFix Compliance is vulnerable to a sensitive information disclosure — BigFix ComplianceCWE-497 5.3 Medium2026-01-28
CVE-2025-62327 HCL DevOps Deploy is susceptible to insufficiently protected credentials — DevOps DeployCWE-522 4.9 Medium2026-01-07
CVE-2025-31964 HCL BigFix IVR is impacted by an improper service binding configuration — BigFix IVRCWE-200 2.2 Low2026-01-07
CVE-2025-31963 HCL BigFix IVR is impacted by improper authentication and missing CSRF protection — BigFix IVRCWE-306 2.9 Low2026-01-07
CVE-2025-31962 HCL BigFix IVR is impacted by an insufficient session expiration vulnerability — BigFix IVRCWE-613 2.0 Low2026-01-07

本页汇总了 HCLSoftware 厂商截至目前公开的全部 79 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。