PatchSiren

HCL CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM HCL CVE published 2026-07-31

CVE-2025-62347

CVE-2025-62347 is a MEDIUM-severity vulnerability affecting HCL iControl, caused by Improper Input Validation. This vulnerability could lead to unexpected system behavior and potential security bypasses. The CVE record was published on 2026-07-31T16:16:56.500Z and was last modified on 2026-09-29T14:10:00.117Z. The NVD entry is currently Deferred. Defenders should assess exposure and verify the vulnerabili [truncated]

HIGH HCL CVE published 2026-06-04

CVE-2025-59874

CVE-2025-59874 is a HIGH severity vulnerability in HCL Hive Telco Observability. A Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2025-59874) and last modified on [cveModifiedAt](https://nvd.nist.gov/vul [truncated]

LOW HCL CVE published 2026-06-04

CVE-2025-52611

CVE-2025-52611 is a low-severity vulnerability (CVSS Score: 3.1) affecting HCL iControl v4.0.0. The issue arises from an unhandled exception leading to stack trace disclosure. This occurs when the application's JavaScript code attempts to access an undefined property, specifically trying to read the 'dashboard' key from an object that has not been properly initialized or is missing.

LOW HCL CVE published 2026-06-04

CVE-2025-52609

CVE-2025-52609 is a LOW-severity vulnerability in HCL iControl, a product from HCL Technologies. The vulnerability is caused by missing security headers, which could lead to cross-site scripting (XSS) attacks. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 3.7. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2025-52609) and last modi [truncated]

LOW HCL CVE published 2026-06-04

CVE-2025-52608

HCL iControl was affected by a Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. The path is also set to root. This vulnerability has a CVSS score of 3.1 and a severity of LOW.

MEDIUM HCL CVE published 2026-06-04

CVE-2025-52606

A medium severity vulnerability, CVE-2025-52606, was found in HCL iControl. The vulnerability is caused by a Weak Input Validation weakness, which occurs during the implementation of an architectural security tactic. The product receives input that is expected to be of a certain type but does not validate or incorrectly validates that the input is actually of the expected type. The Common Vulnerability Sc [truncated]

LOW HCL CVE published 2026-05-20

CVE-2025-31985

CVE-2025-31985 affects HCL BigFix Service Management 23.0 and is described as a security misconfiguration involving a missing or insecure X-Content-Type-Options header. Without that header, browsers may perform MIME-type sniffing and handle content in a way the application did not intend. The record is published as a low-severity issue, but it still matters because it can affect how users' browsers interp [truncated]

MEDIUM HCL CVE published 2026-05-20

CVE-2025-31973

CVE-2025-31973 describes a configuration issue in HCL BigFix Service Management where an insecure or outdated base image version may be used. NVD lists the impact as low in confidentiality, integrity, and availability, with a CVSS 3.1 vector of AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L. The issue was published by NVD on 2026-05-20 and an HCL vendor advisory is referenced for mitigation guidance.

LOW HCL CVE published 2026-05-14

CVE-2025-62317

CVE-2025-62317 is a low-severity vulnerability affecting HCL AION, where sensitive information may be included in URL parameters. This could potentially lead to unintended information disclosure. Defenders should assess exposure and prioritize verification of inventory and compensating controls. The vulnerability exists due to sensitive data being passed in URLs, which may be exposed through browser histo [truncated]

LOW HCL CVE published 2026-05-14

CVE-2025-62316

HCL AION's improper configuration of certain security-related HTTP response headers may reduce browser-based security controls' effectiveness, potentially exposing the application to limited security risks under specific conditions. This issue affects HCL AION deployments, which defenders should assess for exposure and verify HTTP response headers configuration to ensure proper security controls are in pl [truncated]

MEDIUM HCL CVE published 2026-05-14

CVE-2025-62313

CVE-2025-62313 debrief based on the supplied source corpus. The CVE record was published on 2026-05-14T17:16:18.660Z and has not been modified since then. HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced, potentially leading to unauthorized access or account compromise under certain conditions. Defenders should assess exposure and verify auth [truncated]

LOW HCL CVE published 2026-05-14

CVE-2025-62312

CVE-2025-62312 debrief based on the supplied source corpus. The CVE record was published on 2026-05-14T17:16:18.480Z and has not been modified since then. HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. This may expose credentials to potential interception or misuse, especially if not combined with secure transmission practices. Defenders and security [truncated]

MEDIUM HCL CVE published 2026-05-14

CVE-2025-62311

CVE-2025-62311 debrief based on the supplied source corpus. The CVE record was published on 2026-05-14T17:16:18.337Z and has not been modified since then. This medium-severity vulnerability in HCL AION may expose sensitive information due to insecure HTTP channels. Defenders should assess exposure and prioritize secure communication protocols. The vulnerability involves backend service details being trans [truncated]

MEDIUM HCL CVE published 2026-05-14

CVE-2025-62310

CVE-2025-62310 is a medium-severity vulnerability affecting HCL AION, where encryption is not enforced for certain data transmissions or operations. This may expose sensitive information to potential interception or unauthorized access under specific conditions. The vulnerability has been publicly disclosed and defenders responsible for HCL AION deployments should assess exposure and prioritize verifying [truncated]

LOW HCL CVE published 2026-05-14

CVE-2025-62309

CVE-2025-62309 is a low-severity vulnerability affecting HCL AION, where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to unintended exposure under specific conditions. The vulnerability has a CVSS score of 2.6 and is considered low-severity. Defenders responsible for HCL AION systems with sensitive in [truncated]

MEDIUM HCL CVE published 2026-05-14

CVE-2025-62308

CVE-2025-62308 debrief based on the supplied source corpus. The CVE record was published on 2026-05-14T17:16:17.913Z and has not been modified since then. This medium-severity vulnerability in HCL AION may expose sensitive backend infrastructure details, potentially revealing internal system architecture or configuration details. Defenders should assess exposure and verify vendor remediation and updates. [truncated]

MEDIUM HCL CVE published 2026-05-14

CVE-2025-62305

CVE-2025-62305 debrief based on the supplied source corpus. The CVE record was published on 2026-05-14T17:16:16.307Z and has not been modified since then. This vulnerability affects HCL AION, potentially leading to unintended disclosure of sensitive information through out-of-band interactions triggered by certain operations. Defenders should assess exposure, particularly in systems handling sensitive dat [truncated]

MEDIUM HCL CVE published 2026-05-09

CVE-2025-15633

CVE-2025-15633 is an improper authorization issue in HCL BigFix WebUI. According to the CVE description and HCL reference, an authenticated user without Master Operator privileges may access internal data such as site names, versions, and configuration variables through unprotected endpoints, bypassing intended privilege checks. The CVSS score is 5.3 (Medium).

MEDIUM HCL CVE published 2026-05-06

CVE-2025-31960

CVE-2025-31960 is a medium-severity vulnerability in HCL BigFix Service Management (SM) that exposes information due to improper error handling in its reporting module. An attacker can trigger an unhandled exception by supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request. This issue has been publicly disclosed and analyzed by the CVE Program and NIST [truncated]

MEDIUM HCL CVE published 2026-05-06

CVE-2025-52613

CVE-2025-52613 debrief based on the supplied source corpus. The CVE record was published on 2026-05-06T15:16:08.247Z and has not been modified since then. HCL BigFix Service Management (SM) is affected by the use of a vulnerable WSGI Server. This vulnerability could potentially increase the risk of exploitation and unauthorized access. Administrators should verify the WSGI server versions used in their de [truncated]

LOW HCL CVE published 2026-05-06

CVE-2025-31984

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure 'X-Content-Type-Options' header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly. The issue arises from the lack of proper configuration of the 'X-Content-Type-Options' header, which is crucial for preventing MI [truncated]

LOW HCL CVE published 2026-05-06

CVE-2025-31983

A security misconfiguration vulnerability in HCL BigFix Service Management (SM) due to CSP header could allow attackers to inject malicious scripts, increasing the risk of cross-site scripting (XSS) and potential exposure of sensitive information. This vulnerability affects HCL BigFix Service Management (SM) deployments, and defenders should assess the risk and prioritize verifying the CSP header configur [truncated]

LOW HCL CVE published 2026-05-06

CVE-2025-31975

A low-severity information disclosure issue was identified in HCL BigFix Service Management (SM). The vulnerability, known as Information Disclosure – Server Banner, could potentially aid attackers in targeting known vulnerabilities. Defenders and administrators should assess exposure and prioritize verification of server banner configurations to minimize potential risks. This issue was publicly disclosed [truncated]

LOW HCL CVE published 2026-05-06

CVE-2025-62345

HCL BigFix RunBookAI has a vulnerability related to the continued availability of a less-secure 'Input Text' feature. This component's input handling implementation has a security weakness, potentially leading to misconfiguration and operational errors. The CVE was published on 2026-05-06T12:16:26.957Z and was last modified on 2026-09-30T22:10:00.273Z.

HIGH HCL CVE published 2026-05-06

CVE-2025-31951

CVE-2025-31951 is a Unvalidated Command Input / Potential Command Smuggling vulnerability affecting HCL BigFix RunBookAI. A flaw in a component's input handling could permit unauthorized command execution. The CVE record was published on 2026-05-06T12:16:26.087Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. Defenders responsible for HCL BigFix RunBookAI deployments sh [truncated]

LOW HCL CVE published 2026-05-06

CVE-2025-59854

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header. This could allow an attacker to exploit browser-specific rendering flaws or bypass security controls that should be managed by a robust Content Security Policy (CSP). Defenders should assess exposure and prioritize remediation for HCL DFXAnalytics ins [truncated]

LOW HCL CVE published 2026-05-06

CVE-2025-59853

CVE-2025-59853 is an Improper Error Handling vulnerability in HCL DFXAnalytics. The application exposes detailed stack traces in responses, allowing attackers to gain insights into the application's internal structure, code logic, and environment configurations. Defenders responsible for HCL DFXAnalytics deployments, particularly those with versions prior to 4.1, should assess exposure and prioritize miti [truncated]

LOW HCL CVE published 2026-05-06

CVE-2025-59852

CVE-2025-59852 is an Insufficient Transport Layer Protection vulnerability in HCL DFXAnalytics. The vulnerability allows potential confidentiality, integrity, and authentication compromise of sensitive information due to data transmission without encryption. Defenders handling sensitive information in HCL DFXAnalytics deployments should assess exposure and prioritize verification of network data transmiss [truncated]

LOW HCL CVE published 2026-05-06

CVE-2025-59851

CVE-2025-59851 debrief based on the supplied source corpus. The CVE record was published on 2026-05-06T11:16:04.440Z and has not been modified since then. HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, potentially allowing attackers to identify and exploit publicly known security vulnerabilities to ga [truncated]

MEDIUM HCL CVE published 2026-05-06

CVE-2025-31970

HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection vectors such as Cross-Site Scripting (XSS). The vulnerability exists due to a misconfigured Content-Security-Policy, allowing potential attackers to inject malicious script [truncated]