CVE-2026-56609
- EPSS 0.1%
- Veröffentlicht 03.08.2026 11:26:07
- Zuletzt bearbeitet 05.08.2026 14:56:40
HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to know...
CVE-2026-56608
- EPSS 0.16%
- Veröffentlicht 03.08.2026 11:25:35
- Zuletzt bearbeitet 05.08.2026 14:56:20
HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.
CVE-2026-56571
- EPSS 0.17%
- Veröffentlicht 31.07.2026 15:13:17
- Zuletzt bearbeitet 05.08.2026 14:55:36
HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be gener...
CVE-2026-56570
- EPSS 0.18%
- Veröffentlicht 31.07.2026 14:59:02
- Zuletzt bearbeitet 05.08.2026 14:32:31
HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers m...
CVE-2026-56569
- EPSS 0.1%
- Veröffentlicht 31.07.2026 14:57:47
- Zuletzt bearbeitet 05.08.2026 14:31:52
HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
CVE-2026-56568
- EPSS 0.2%
- Veröffentlicht 31.07.2026 14:54:05
- Zuletzt bearbeitet 06.08.2026 14:46:46
HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint ...
CVE-2026-56567
- EPSS 0.1%
- Veröffentlicht 31.07.2026 14:52:27
- Zuletzt bearbeitet 06.08.2026 14:44:44
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
CVE-2025-62340
- EPSS 0.2%
- Veröffentlicht 17.06.2026 12:17:23
- Zuletzt bearbeitet 06.10.2026 22:10:00
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
CVE-2025-52606
- EPSS 0.17%
- Veröffentlicht 04.06.2026 11:56:42
- Zuletzt bearbeitet 22.07.2026 20:10:00
HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly vali...
CVE-2025-52608
- EPSS 0.1%
- Veröffentlicht 04.06.2026 11:49:16
- Zuletzt bearbeitet 22.07.2026 20:10:00
HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.