Hcltech
Hcltech Connections: vulnerabilidades y CVE
Hcltech Connections tiene 24 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-56538 | Baja (3.5) | 0.27% | — | 27 jul 2026 | An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users. |
| CVE-2026-56537 | Baja (3.5) | 0.27% | — | 27 jul 2026 | HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by… |
| CVE-2026-21788 | Media (5.4) | 0.16% | — | 19 mar 2026 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script… |
| CVE-2025-52603 | Baja (3.5) | 0.27% | — | 20 feb 2026 | HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow a user to obtain limited information when a single piece of internal metadata is returned in the… |
| CVE-2025-52639 | Media (6.5) | 0.21% | — | 18 nov 2025 | HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper rendering of application data. |
| CVE-2025-31961 | Media (4.6) | 0.15% | — | 15 ago 2025 | HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios. |
| CVE-2024-42209 | Baja (3.5) | 0.20% | — | 17 jul 2025 | HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive information they are not entitled to, which is caused by improper handling of request data. |
| CVE-2024-42208 | Baja (3.5) | 0.27% | — | 4 abr 2025 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data. |
| CVE-2024-42188 | Media (4.6) | 0.18% | — | 14 nov 2024 | HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios. |
| CVE-2024-30106 | Media (4.3) | 0.27% | — | 28 oct 2024 | HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entitled to due to the… |
| CVE-2024-30118 | Media (5.7) | 0.31% | — | 9 oct 2024 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly handling the request data. |
| CVE-2024-30112 | Media (5.4) | 0.26% | — | 25 jun 2024 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script… |
| CVE-2023-37541 | Media (4.3) | 0.33% | — | 25 jun 2024 | HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios. |
| CVE-2024-30107 | Media (6.5) | 0.33% | — | 18 abr 2024 | HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios. |
| CVE-2024-23557 | Media (4.3) | 0.35% | — | 18 abr 2024 | HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack. |
| CVE-2023-28018 | Media (6.5) | 0.32% | — | 12 feb 2024 | HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for… |
| CVE-2023-28022 | Media (6.5) | 0.50% | — | 15 dic 2023 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data. |
| CVE-2023-28017 | Media (5.4) | 0.41% | — | 7 dic 2023 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which… |
| CVE-2023-37533 | Media (6.1) | 0.42% | — | 9 nov 2023 | HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL… |
| CVE-2019-4209 | Media (6.1) | 0.64% | — | 1 may 2020 | HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks. |
| CVE-2020-4085 | Media (6.5) | 0.82% | — | 22 abr 2020 | "HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user." |
| CVE-2020-4084 | Media (5.4) | 0.52% | — | 9 mar 2020 | HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading… |
| CVE-2020-4083 | Media (5.5) | 0.35% | — | 5 mar 2020 | HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user. |
| CVE-2020-4082 | Media (5.4) | 0.66% | — | 5 mar 2020 | The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to… |