These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The HCL iControl application, used for managing and monitoring HCL products, is affected by a Missing Access Control vulnerability. This vulnerability class allows users to access or view administrator-level functionalities without appropriate authorization, potentially leading to unauthorized access attempts. The CVE record was published on 2026-08-03T13:18:52.257Z and has not been modified since then. O [truncated]
The HCL iControl system has an Auto complete Enabled vulnerability, potentially exposing sensitive information such as valid usernames, email addresses, and account identifiers in shared environments. This vulnerability was published on 2026-07-31T16:17:07.637Z and has not been modified since then. Administrators and users of HCL iControl systems, especially those accessed from shared environments, should [truncated]
HCL iControl was affected by Sensitive Data Exposure vulnerabilities due to improper web server or application hardening. This could lead to the public exposure of internal configuration files. Administrators and users of HCL iControl, as well as organizations relying on this software for critical operations, should review and apply vendor remediation if available. They should also verify and update affec [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-56567 was published on 2026-07-31T16:17:07.290Z and has not been modified since then. HCL iControl v4.3.0 is affected by Security Misconfiguration vulnerabilities due to improper web server or application hardening, leading to public exposure of internal configuration files. Organizations using HCL iControl v4. [truncated]
CVE-2024-23564 is a critical business logic vulnerability in HCL Aftermarket EPC that allows a non-valid user to obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwo [truncated]
HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Security teams and administrators responsible for HCL [truncated]
HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system to crash or become unresponsive. This vulnerability has a CVSS score of 5.3 and is classified as a Medium priority due to its po [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-16T14:16:54.643Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to int [truncated]
CVE-2026-56453 is an Account Takeover via Response Manipulation vulnerability affecting HCL DFXAnalytics. A remote attacker can intercept and alter server HTTP responses before they reach the client application, allowing them to manipulate authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts. This type of vulnerability typically allows attackers t [truncated]
The CVE record for CVE-2026-35143 was published on 2026-07-16T14:16:50.973Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This CVE is related to a Missing SameSite Attribute vulnerability in HCL DFXAnalytics, which could allow Cross-Site Request Forgery (CSRF) attacks if additional mitigations are not implemented.
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks. This vulnerability has a CVSS score of 2.6 and a severity of LOW. The CVE [truncated]
A Login Replay Attack vulnerability was discovered in HCL DFXAnalytics. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejec [truncated]
The CVE-2026-35140 record indicates a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL DFXAnalytics. The application fails to set the 'secure' attribute on session cookies generated during authentication, potentially allowing remote attackers to intercept network traffic and capture sensitive cookies, session tokens, or credentials. Users of HCL DFXAnalytics should review th [truncated]
CVE-2026-35149 is an Authentication Bypass vulnerability in HCL DFXServer. An unauthorized user can exploit this flaw by intercepting and altering the server's authentication responses. This vulnerability allows an unauthorized user to gain access to the application without verification by manipulating server authentication responses. Users of HCL DFXServer should be aware of this Authentication Bypass vu [truncated]
CVE-2026-35148 is a Missing Access Control vulnerability in HCL DFXServer, allowing network users to invoke APIs and interact with the application without verification of identity or authorization level. The vulnerability has a CVSS score of 6.3 and a severity of MEDIUM. Users of HCL DFXServer should assess and mitigate this vulnerability to prevent unauthorized access. The CVE record was published on 202 [truncated]
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials. This vulnerability has a high CVSS score of 8.2 and is classified as HIGH severity. Securit [truncated]
A low-severity vulnerability, CVE-2025-62340, was discovered in HCL iControl, related to inadequate session timeout. This issue involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity. The vulnerability has a CVSS score of 3.1 and is considered low severity. The CVE was published on 2026-06-17T13:19:15.840Z and last modified on 2026-06-1 [truncated]
HCL ZIE for Web is affected by an Unrestricted File Upload vulnerability. If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be c [truncated]
CVE-2025-15634 describes a missing authorization flaw in HCL BigFix WebUI. An authenticated user without the proper permissions may be able to reach an unauthorized page directly by URL and view sensitive environmental information. The issue is rated medium severity and maps to CWE-862 (missing authorization).
CVE-2025-31978 is a medium-severity vulnerability (CVSS Score: 4.6) affecting HCL BigFix Service Management. The issue lies in the inadequate sanitization or safe rendering of spreadsheet files (CSV, XLS, XLSX) before processing or distribution. An attacker could exploit this by populating data fields in a way that, when saved to a CSV file, may attempt information exfiltration or other malicious activiti [truncated]
HCL BigFix Service Management (SM) has a vulnerability that involves insufficiently protected credentials for a short duration while communicating with a backend, internal application. This could potentially allow an attacker to misuse the credentials if they are exfiltrated. The vulnerability has a CVSS score of 4.8 and is classified as medium severity. The CVE was published on May 6, 2026, and last modi [truncated]