hcltech
48 known vulnerabilities affecting hcltech products.
Products
icontrol 12
dryice_mycloud 7
devops_plan 5
dfx_server 4
devops_loop 4
intelliops_event_management 4
digital_experience 3
digital_experience_compose 3
devops_velocity 3
bigfix_service_management 2
bigfix_webui_api 2
bigfix_webui_application_administration 2
bigfix_webui_cmep 2
bigfix_webui_common 2
bigfix_webui_content_app 2
bigfix_webui_custom 2
bigfix_webui_data_sync 2
bigfix_webui_extensions 2
bigfix_webui_framework 2
bigfix_webui_insights 2
bigfix_webui_ivr 2
bigfix_webui_mdm 2
bigfix_webui_patch 2
bigfix_webui_patch_policies 2
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-21837 | Medium | 0.9% | 8.8 | HCL Digital Experience is affected by an OS command injection vulnerability in t… | |
| CVE-2026-35147 | Medium | 0.4% | 8.2 | HCL DFXServer is affected by a Broken Authentication vulnerability via direct AP… | |
| CVE-2026-35149 | Medium | 0.4% | 8.2 | HCL DFXServer is affected by an Authentication Bypass vulnerability via server r… | |
| CVE-2023-37507 | Medium | 0.2% | 7.5 | HCL DevOps Plan is susceptible to an information disclosure that can allow an at… | |
| CVE-2025-52612 | Medium | 0.2% | 7.1 | HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vul… | |
| CVE-2024-22348 | Low | 0.4% | 5.3 | IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses … | |
| CVE-2024-22347 | Low | 0.3% | 5.9 | IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses … | |
| CVE-2026-35148 | Low | 0.3% | 6.3 | HCL DFXServer is affected by a Missing Access Control vulnerability. This vulner… | |
| CVE-2026-56580 | Low | 0.3% | 2.2 | HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Serv… | |
| CVE-2026-56578 | Low | 0.3% | 2.2 | HCL MyCloud was affected by Server Version Disclosure. It may help attackers ide… | |
| CVE-2026-56579 | Low | 0.2% | 3.1 | HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enab… | |
| CVE-2026-56587 | Low | 0.2% | 3.7 | HCL IEM was affected with Strict transport security not enforced. It may enable … | |
| CVE-2025-36363 | Low | 0.2% | 5.9 | IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting t… | |
| CVE-2025-15633 | Low | 0.2% | 6.5 | An improper authorization vulnerability in HCL BigFix WebUI allows an authentica… | |
| CVE-2026-56583 | Low | 0.2% | 3.1 | HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase th… | |
| CVE-2024-22349 | Low | 0.2% | 4.0 | IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allow… | |
| CVE-2026-21760 | Low | 0.2% | 4.6 | HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Fo… | |
| CVE-2026-56568 | Low | 0.2% | 3.7 | HCL iControl was affected by Information Exposure Through Verbose Client-Side AP… | |
| CVE-2026-35146 | Low | 0.2% | 6.3 | HCL DFXServer is affected by an Unencrypted Communication vulnerability. The app… | |
| CVE-2025-15634 | Low | 0.2% | 4.3 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticate… | |
| CVE-2025-31973 | Low | 0.2% | 4.0 | HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecur… | |
| CVE-2026-56570 | Low | 0.2% | 3.7 | HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves … | |
| CVE-2026-21762 | Low | 0.2% | 3.7 | HCL DevOps Loop is affected by missing HTTP security headers. Missing security h… | |
| CVE-2026-56571 | Low | 0.2% | 3.7 | HCL iControl was affected by Improper Error Handling vulnerabilities. It involve… | |
| CVE-2026-56584 | Low | 0.2% | 3.7 | HCL IEM was affected with the Information disclosure nginx server. It may enable… | |
| CVE-2025-52606 | Low | 0.2% | 4.3 | HCL iControl was affected by Weak Input Validation vulnerability. This weakness … | |
| CVE-2026-56577 | Low | 0.2% | 3.1 | HCL MyCloud was affected with Weak Password Policy. It may increase the risk of … | |
| CVE-2026-56608 | Low | 0.2% | 3.7 | HCL iControl is affected by Missing Access Control vulnerability. The applicatio… | |
| CVE-2025-52609 | Low | 0.2% | 3.7 | HCL iControl was affected by Missing Security Headers vulnerability. which lead … | |
| CVE-2026-56537 | Low | 0.2% | 3.5 | HCL Connections is vulnerable to information disclosure which could allow a user… | |
| CVE-2026-56538 | Low | 0.2% | 3.5 | An endpoint in HCL Connections is vulnerable to information disclosure. In certa… | |
| CVE-2025-31985 | Low | 0.2% | 3.7 | HCL BigFix Service Management (SM) is affected by a security misconfiguration du… | |
| CVE-2025-52611 | Low | 0.2% | 3.1 | HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure… | |
| CVE-2026-56582 | Low | 0.2% | 3.1 | HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may e… | |
| CVE-2026-56581 | Low | 0.2% | 2.6 | HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the… | |
| CVE-2026-21825 | Low | 0.2% | 6.1 | HCL Digital Experience Compose is affected by a reflected cross-site scripting (… | |
| CVE-2026-4096 | Low | 0.1% | 6.5 | IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caus… | |
| CVE-2026-21761 | Low | 0.1% | 4.2 | HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfigu… | |
| CVE-2026-56585 | Low | 0.1% | 3.1 | HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. I… | |
| CVE-2026-21826 | Low | 0.1% | 6.1 | HCL Digital Experience and HCL Digital Experience Compose could be susceptible t… | |
| CVE-2026-21764 | Low | 0.1% | 3.1 | HCL DevOps Loop is affected by insufficient input validation that allows special… | |
| CVE-2023-37508 | Low | 0.1% | 6.1 | HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which c… | |
| CVE-2026-56586 | Low | 0.1% | 3.1 | HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable a… | |
| CVE-2025-36364 | Low | 0.1% | 6.2 | IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally w… | |
| CVE-2026-56567 | Low | 0.1% | 5.1 | HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. I… | |
| CVE-2026-56569 | Low | 0.1% | 4.0 | HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involve… | |
| CVE-2025-52608 | Low | 0.1% | 3.1 | HCL iControl was affected by Missing Cookie Attributes vulnerability. It was ob… | |
| CVE-2026-56609 | Low | 0.1% | 4.8 | HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was… |