-Infinity
0
Severity
9.8
SQL Injection
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run arbitrary SQL commands including changing system configuration.

First published (updated )
Severity
9.8
Input Validation
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into a system which can cause the system to behave in unexpected ways.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can affect any application with access control, including databases, network infrastructure, and web applications.

First published (updated )
Severity
9.8
Input Validation, Buffer Overflow, XSS, SQL Injection
AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N

HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. This can lead to security vulnerabilities like SQL injection, XSS, and buffer overflow.

First published (updated )
Severity
9.8
Malicious File Upload
AV:P/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N

HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.

First published (updated )
Severity
9.8
Weak Encryption
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts.

First published (updated )
Severity
9.8
AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

First published (updated )
Severity
9.8
AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

First published (updated )
Severity
9.8
SQL Injection
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL queries.

First published (updated )
Severity
9.8
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

A

rusted types in scripts not enforced in CSP vulnerability has been identified

in HCL AION.This issue affects AION: 2.0.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. An attacker can exploit use this information to exploit known vulnerabilities launch targeted attacks, such as remote code execution or denial of service.

First published (updated )
Severity
9.8
SSRF, Input Validation
AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:L

HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can exploit improper input validation by submitting maliciously crafted input to a target application running on a server.

First published (updated )
Severity
9.8
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk

First published (updated )
Severity
9.8
Malicious File Upload
AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

First published (updated )
Severity
9.8
Malicious File Upload
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

First published (updated )
Severity
9.8
AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N

HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable passwords, potentially resulting in unauthorized access

First published (updated )
Severity
9.8
OS Command Injection, Command Injection
AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

A Potential Command Injection vulnerability in HCL AION.

An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AION: 2.0

First published (updated )
Severity
9.8
AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system

First published (updated )
Severity
9.8
Malicious File Upload
AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server.

First published (updated )
Severity
9.8
AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts.

First published (updated )
Severity
9.8
Input Validation, XSS, SQL Injection, Command Injection
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS, SQL Injection, Command Injection etc.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise the application and may steal and manipulate the data.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.

First published (updated )
Severity
9.8
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, which could allow an attacker to identify and exploit publicly known security vulnerabilities to gain unauthorized access or compromise the application.

First published (updated )
Severity
9.8
AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.

First published (updated )
Severity
9.8
Malicious File Upload
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code

First published (updated )
Severity
9.8
AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts.

First published (updated )
Severity
9.4
SSRF
AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, and then induce the application to retrieve and process that content.

First published (updated )
Severity
9.1
SSRF
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks from unauthenticated users.

First published (updated )
Severity
9.1
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203