PatchSiren

HCL Software CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW HCL Software CVE published 2026-07-16

CVE-2026-35142

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks. This vulnerability has a CVSS score of 2.6 and a severity of LOW. The CVE [truncated]

LOW HCL Software CVE published 2026-07-16

CVE-2026-35141

A Login Replay Attack vulnerability was discovered in HCL DFXAnalytics. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejec [truncated]

LOW HCL Software CVE published 2026-07-16

CVE-2026-35140

The CVE-2026-35140 record indicates a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL DFXAnalytics. The application fails to set the 'secure' attribute on session cookies generated during authentication, potentially allowing remote attackers to intercept network traffic and capture sensitive cookies, session tokens, or credentials. Users of HCL DFXAnalytics should review th [truncated]

HIGH HCL Software CVE published 2026-07-16

CVE-2026-35149

CVE-2026-35149 is an Authentication Bypass vulnerability in HCL DFXServer. An unauthorized user can exploit this flaw by intercepting and altering the server's authentication responses. This vulnerability allows an unauthorized user to gain access to the application without verification by manipulating server authentication responses. Users of HCL DFXServer should be aware of this Authentication Bypass vu [truncated]

MEDIUM HCL Software CVE published 2026-07-16

CVE-2026-35148

CVE-2026-35148 is a Missing Access Control vulnerability in HCL DFXServer, allowing network users to invoke APIs and interact with the application without verification of identity or authorization level. The vulnerability has a CVSS score of 6.3 and a severity of MEDIUM. Users of HCL DFXServer should assess and mitigate this vulnerability to prevent unauthorized access. The CVE record was published on 202 [truncated]

HIGH HCL Software CVE published 2026-07-16

CVE-2026-35147

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials. This vulnerability has a high CVSS score of 8.2 and is classified as HIGH severity. Securit [truncated]

LOW HCL Software CVE published 2026-06-17

CVE-2025-62340

A low-severity vulnerability, CVE-2025-62340, was discovered in HCL iControl, related to inadequate session timeout. This issue involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity. The vulnerability has a CVSS score of 3.1 and is considered low severity. The CVE was published on 2026-06-17T13:19:15.840Z and last modified on 2026-06-1 [truncated]

MEDIUM HCL Software CVE published 2026-06-17

CVE-2025-59872

HCL ZIE for Web is affected by an Unrestricted File Upload vulnerability. If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be c [truncated]

MEDIUM HCL Software CVE published 2026-05-09

CVE-2025-15634

CVE-2025-15634 describes a missing authorization flaw in HCL BigFix WebUI. An authenticated user without the proper permissions may be able to reach an unauthorized page directly by URL and view sensitive environmental information. The issue is rated medium severity and maps to CWE-862 (missing authorization).

LOW HCL Software CVE published 2026-05-06

CVE-2025-31982

CVE-2025-31982 debrief based on the supplied source corpus. HCL BigFix Service Management (SM) 23.0 had directories that were not linked or publicly visible but could be accessed directly, potentially allowing information disclosure or misuse of sensitive functionality. Defenders and administrators should assess exposure, verify inventory, and review directory permissions. The CVE record and NVD entry pro [truncated]

MEDIUM HCL Software CVE published 2026-05-06

CVE-2025-31978

CVE-2025-31978 is a medium-severity vulnerability (CVSS Score: 4.6) affecting HCL BigFix Service Management. The issue lies in the inadequate sanitization or safe rendering of spreadsheet files (CSV, XLS, XLSX) before processing or distribution. An attacker could exploit this by populating data fields in a way that, when saved to a CSV file, may attempt information exfiltration or other malicious activiti [truncated]

MEDIUM HCL Software CVE published 2026-05-06

CVE-2025-31976

HCL BigFix Service Management (SM) has a vulnerability that involves insufficiently protected credentials for a short duration while communicating with a backend, internal application. This could potentially allow an attacker to misuse the credentials if they are exfiltrated. The vulnerability has a CVSS score of 4.8 and is classified as medium severity. The CVE was published on May 6, 2026, and last modi [truncated]

LOW HCL Software CVE published 2026-05-06

CVE-2025-31959

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images, potentially leading to confidentiality and privacy risks if sensitive location information is unintentionally shared. This vulnerability requires assessment and remediation to prevent potential confidentiality and privacy risks. The affected product is HCL BigFix Service Management, and the vulnerability clas [truncated]

LOW HCL Software CVE published 2026-05-06

CVE-2025-31957

A Cross-Site Request Forgery (CSRF) vulnerability affects HHCL BigFix Service Management (SM), potentially leading to unauthorized changes or exposure of sensitive data. Defenders should assess exposure, particularly those managing web applications and CSRF protections. The vulnerability has a CVSS score of 2.6 and is considered low severity. To verify and remediate, review the official CVE Program record [truncated]