Filtered by vendor Hcltech Subscriptions
Total 193 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-14240 1 Hcltech 1 Notes 2024-11-21 6.1 Medium
HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.
CVE-2020-14234 1 Hcltech 1 Domino 2024-11-21 7.5 High
HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the ability to crash the server. Versions previous to release 9.0.1 FP10 IF6 and release 10.0.1 are affected.
CVE-2020-14232 1 Hcltech 1 Notes 2024-11-21 8.8 High
A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the privileges of the currently logged in user.
CVE-2020-14230 1 Hcltech 1 Domino 2024-11-21 7.5 High
HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the server. Versions previous to releases 9.0.1 FP10 IF6, 10.0.1 FP5 and 11.0.1 are affected.
CVE-2020-14225 2 Hcltech, Hcltechsw 2 Hcl Inotes, Hcl Inotes 2024-11-21 6.5 Medium
HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack.
CVE-2020-14224 1 Hcltech 1 Notes 2024-11-21 9.8 Critical
A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the Notes application or inject code into the system which would execute with the privileges of the currently logged-in user.
CVE-2020-14223 1 Hcltech 1 Digital Experience 2024-11-21 6.1 Medium
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.
CVE-2020-14222 1 Hcltech 1 Hcl Digital Experience 2024-11-21 6.1 Medium
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
CVE-2020-14221 1 Hcltech 1 Digital Experience 2024-11-21 4.9 Medium
HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.
CVE-2019-4409 1 Hcltech 1 Traveler 2024-11-21 5.4 Medium
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message that includes the entered file name. If the file name is not escaped in the returned error page, it could expose a cross-site scripting (XSS) vulnerability.
CVE-2019-4393 1 Hcltech 1 Appscan 2024-11-21 9.8 Critical
HCL AppScan Standard is vulnerable to excessive authorization attempts
CVE-2019-4392 1 Hcltech 1 Appscan 2024-11-21 9.8 Critical
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.
CVE-2019-4391 1 Hcltech 1 Appscan 2024-11-21 8.2 High
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
CVE-2019-4388 1 Hcltech 1 Appscan Source 2024-11-21 4.8 Medium
HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.
CVE-2019-4327 1 Hcltech 1 Appscan 2024-11-21 7.5 High
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
CVE-2019-4326 1 Hcltech 1 Appscan 2024-11-21 7.5 High
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
CVE-2019-4325 1 Hcltech 1 Appscan 2024-11-21 5.3 Medium
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
CVE-2019-4324 1 Hcltech 1 Appscan 2024-11-21 6.1 Medium
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
CVE-2019-4323 1 Hcltech 1 Appscan 2024-11-21 4.3 Medium
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
CVE-2019-4301 1 Hcltech 1 Self-service Application 2024-11-21 8.4 High
BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Running Message or Post Message HTML.