SecAlerts
hcltech logo

hcltech

Security Risk Profile

44
/100
medium

Security Risk Score

Comprehensive risk assessment based on 395 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

πŸ“… Data spans from May 30, 2018 to present

395
Total CVEs
173
Critical+High
0
Exploited
159
Unpatched

Threat Assessment

Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
159
Critical/High
Risk Level
44/100
medium
πŸ†• 2Fresh (<7d)πŸ“ˆ 21 in Last 30 Days

Severity Distribution

Critical
51
High
122
Medium
205
Low
17

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
XSS
71
2
Infoleak
27
3
Buffer Overflow
15
4
CSRF
14
5
Input Validation
13

Most Affected Products

1. hcltech Notes256
2. hcltech Domino235
3. hcltech Connections134
4. hcltech Hcl Inotes92
5. hcltech Bigfix Platform77

Recent Vulnerabilities

See more β†’
CVE-2025-31985
CVSS 6.5medium

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure β€œX-Content-Type-Options” header

5/20/2026πŸ”§ No Patch
CVE-2025-31973
CVSS 9.8critical

HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'

5/20/2026πŸ”§ No Patch
CVE-2025-15634
CVSS 5.3medium

HCL BigFix WebUI is affected by a missing authorization vulnerability

5/9/2026πŸ”§ No Patch
CVE-2025-15633
CVSS 5.3medium

HCL BigFix WebUI is affected by an improper authorization vulnerability

5/9/2026πŸ”§ No Patch
CVE-2024-30151
CVSS 8.3high

HCL BigFix Service Management (SM) is susceptible to Broken Access Control Vulnerability

5/6/2026πŸ”§ No Patch
CVE-2025-31960
CVSS 5.3medium

HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module

5/6/2026πŸ”§ No Patch
CVE-2025-31974
CVSS 7.2high

HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only

5/6/2026πŸ”§ No Patch
CVE-2025-31975
CVSS 5.3medium

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified.

5/6/2026πŸ”§ No Patch
CVE-2025-52613
CVSS 8.8high

HCL BigFix Service Management (SM) is affected by use of a vulnerable component

5/6/2026πŸ”§ No Patch
CVE-2025-31976
CVSS 7.5high

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials

5/6/2026πŸ”§ No Patch

Monitor hcltech in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

Β© 2026 SecAlerts Pty Ltd. All rights reserved.