<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0"
 xmlns:dc="http://purl.org/dc/elements/1.1/"
 xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
 xmlns:admin="http://webns.net/mvcb/"
 xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
 xmlns:content="http://purl.org/rss/1.0/modules/content/"
 xmlns:wfw="http://wellformedweb.org/CommentAPI/">
<channel><title>CYONE Security Blog about HCL Software</title><description></description><link>http://update.cyone.lv/security.nsf/</link><language>en-us</language><lastBuildDate>Mon, 20 Apr 2026 08:43:21 +0300</lastBuildDate>
<item><title>Security Bulletin: HCL Verse is susceptible to multiple open source vulnerabilities. Score:  6.5 (Medium)</title><pubDate>Mon, 20 Apr 2026 08:43:21 +0300</pubDate><description><![CDATA[ Summary HCL Verse is susceptible to open source vulnerabilities in the moment, jsoup, commons-fileupload and tinymce components. Vulnerability Details CVE-ID: CVE-2022-31129 Description: moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected ve]]></description><link>http://update.cyone.lv/security.nsf/dx/20.04.2026084321RMI8QN.htm</link><dc:subject>Verse</dc:subject><dc:creator>Roman Mirolubov</dc:creator><comments>http://update.cyone.lv/security.nsf/dx/20.04.2026084321RMI8QN.htm?opendocument&amp;comments</comments><guid isPermaLink="true">http://update.cyone.lv/security.nsf/dx/20.04.2026084321RMI8QN.htm</guid><wfw:commentRss> http://update.cyone.lv/security.nsf/dxcomments/20.04.2026084321RMI8QN.htm</wfw:commentRss><wfw:comment> http://update.cyone.lv/security.nsf/dx/20.04.2026084321RMI8QN.htm?opendocument&amp;comments</wfw:comment></item>
<item><title>Security Bulletin: An SSL certificate host verification vulnerability affects HCL Verse for Android. Score: 6.3 (Medium)</title><pubDate>Mon, 20 Apr 2026 08:34:36 +0300</pubDate><description><![CDATA[ Summary When an SSL certificate is invalid or malicious, a lack of hostname verification might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. HCL Verse for Android might connect to a malicious host while believing it is a trusted host or be deceived into acc]]></description><link>http://update.cyone.lv/security.nsf/dx/20.04.2026083436RMI8K8.htm</link><dc:subject>Verse</dc:subject><dc:creator>Roman Mirolubov</dc:creator><comments>http://update.cyone.lv/security.nsf/dx/20.04.2026083436RMI8K8.htm?opendocument&amp;comments</comments><guid isPermaLink="true">http://update.cyone.lv/security.nsf/dx/20.04.2026083436RMI8K8.htm</guid><wfw:commentRss> http://update.cyone.lv/security.nsf/dxcomments/20.04.2026083436RMI8K8.htm</wfw:commentRss><wfw:comment> http://update.cyone.lv/security.nsf/dx/20.04.2026083436RMI8K8.htm?opendocument&amp;comments</wfw:comment></item>
<item><title>Security Bulletin: Multiple open source vulnerabilities impact HCL SafeLinx      Score: 9.8 (Critical) 🚨🚨🚨</title><pubDate>Tue, 7 Apr 2026 09:26:12 +0300</pubDate><description><![CDATA[ Summary HCL SafeLinx is impacted by multiple open source vulnerabilities. Security Bulletin: Multiple open source vulnerabilities impact HCL SafeLinx https://support.hcl-software.com/csm?id=kb_article&amp;sysparm_article=KB0129920 Vulnerability Details CVE-ID: CVE-2022-37434 Description: zlib th]]></description><link>http://update.cyone.lv/security.nsf/dx/07042026092612VTA9KG.htm</link><dc:subject>SafeLinx</dc:subject><dc:creator>Vladislav Tatarincev</dc:creator><comments>http://update.cyone.lv/security.nsf/dx/07042026092612VTA9KG.htm?opendocument&amp;comments</comments><guid isPermaLink="true">http://update.cyone.lv/security.nsf/dx/07042026092612VTA9KG.htm</guid><wfw:commentRss> http://update.cyone.lv/security.nsf/dxcomments/07042026092612VTA9KG.htm</wfw:commentRss><wfw:comment> http://update.cyone.lv/security.nsf/dx/07042026092612VTA9KG.htm?opendocument&amp;comments</wfw:comment></item>
<item><title>Security Bulletin: Multiple open source vulnerabilities impact HCL Verse Score: 8.2 (High) 🔥</title><pubDate>Wed, 1 Apr 2026 10:41:01 +0300</pubDate><description><![CDATA[ Summary HCL Verse is impacted by vulnerabilities in multiple open source components. Vulnerability Details CVE-ID: CVE-2026-27601 Description: Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under]]></description><link>http://update.cyone.lv/security.nsf/dx/01.04.2026104100RMIB27.htm</link><dc:subject>Verse</dc:subject><dc:creator>Roman Mirolubov</dc:creator><comments>http://update.cyone.lv/security.nsf/dx/01.04.2026104100RMIB27.htm?opendocument&amp;comments</comments><guid isPermaLink="true">http://update.cyone.lv/security.nsf/dx/01.04.2026104100RMIB27.htm</guid><wfw:commentRss> http://update.cyone.lv/security.nsf/dxcomments/01.04.2026104100RMIB27.htm</wfw:commentRss><wfw:comment> http://update.cyone.lv/security.nsf/dx/01.04.2026104100RMIB27.htm?opendocument&amp;comments</wfw:comment></item>
<item><title>Security Bulletin: Impact of Stored Cross-Site Scripting (XSS) Vulnerability on HCL Verse (CVE-2023-37496) Score: 8.3 (High) 🔥</title><pubDate>Mon, 30 Mar 2026 08:27:42 +0300</pubDate><description><![CDATA[ Overview HCL Verse is affected by a stored cross-site scripting (XSS) vulnerability. An attacker could exploit this vulnerability to execute scripts in a user’s web browser and potentially obtain the]]></description><link>http://update.cyone.lv/security.nsf/dx/30.03.2026082742RMI8EW.htm</link><dc:subject>Verse</dc:subject><dc:creator>Roman Mirolubov</dc:creator><comments>http://update.cyone.lv/security.nsf/dx/30.03.2026082742RMI8EW.htm?opendocument&amp;comments</comments><guid isPermaLink="true">http://update.cyone.lv/security.nsf/dx/30.03.2026082742RMI8EW.htm</guid><wfw:commentRss> http://update.cyone.lv/security.nsf/dxcomments/30.03.2026082742RMI8EW.htm</wfw:commentRss><wfw:comment> http://update.cyone.lv/security.nsf/dx/30.03.2026082742RMI8EW.htm?opendocument&amp;comments</wfw:comment></item>
<item><title>Security Bulletin: The HCL Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability CVE-2023-37539 8.4 (High) 🔥</title><pubDate>Fri, 27 Mar 2026 11:15:39 +0300</pubDate><description><![CDATA[ Summary The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. Databases created from this template are impacted by this vulnerability. Vulnerability Detail]]></description><link>http://update.cyone.lv/security.nsf/dx/27032026111539VTACVC.htm</link><dc:subject></dc:subject><dc:creator>Vladislav Tatarincev</dc:creator><comments>http://update.cyone.lv/security.nsf/dx/27032026111539VTACVC.htm?opendocument&amp;comments</comments><guid isPermaLink="true">http://update.cyone.lv/security.nsf/dx/27032026111539VTACVC.htm</guid><wfw:commentRss> http://update.cyone.lv/security.nsf/dxcomments/27032026111539VTACVC.htm</wfw:commentRss><wfw:comment> http://update.cyone.lv/security.nsf/dx/27032026111539VTACVC.htm?opendocument&amp;comments</wfw:comment></item>
<item><title>Security Bulletin: HCL Notes is affected by an XML External Entity (XXE) vulnerability in Apache Tika (CVE-2025-54988) Score: 8.4 (high) 🔥</title><pubDate>Thu, 26 Mar 2026 16:12:10 +0300</pubDate><description><![CDATA[ Summary An XXE vulnerability in Apache Tika impacts HCL Notes. An unauthenticated attacker could leverage this vulnerability to carry out an injection attack. Vulnerability Details CVE-ID: CVE-2025]]></description><link>http://update.cyone.lv/security.nsf/dx/26032026161210VTAJNN.htm</link><dc:subject>Notes</dc:subject><dc:creator>Vladislav Tatarincev</dc:creator><comments>http://update.cyone.lv/security.nsf/dx/26032026161210VTAJNN.htm?opendocument&amp;comments</comments><guid isPermaLink="true">http://update.cyone.lv/security.nsf/dx/26032026161210VTAJNN.htm</guid><wfw:commentRss> http://update.cyone.lv/security.nsf/dxcomments/26032026161210VTAJNN.htm</wfw:commentRss><wfw:comment> http://update.cyone.lv/security.nsf/dx/26032026161210VTAJNN.htm?opendocument&amp;comments</wfw:comment></item>
<item><title>Security Bulletin: HCL Nomad for Android is susceptible to a cookie overflow vulnerability in libcurl (CVE-2025-9086) Score: 7.5 (high) 🔥</title><pubDate>Thu, 26 Mar 2026 14:58:53 +0300</pubDate><description><![CDATA[ Summary HCL Nomad for Android is susceptible to a cookie overflow vulnerability in libcurl. Vulnerability Details CVE-ID: CVE-2025-9086 Description: 1. A cookie is set using the `secure` keyword]]></description><link>http://update.cyone.lv/security.nsf/dx/26032026145853VTAH8U.htm</link><dc:subject>Nomad</dc:subject><dc:creator>Vladislav Tatarincev</dc:creator><comments>http://update.cyone.lv/security.nsf/dx/26032026145853VTAH8U.htm?opendocument&amp;comments</comments><guid isPermaLink="true">http://update.cyone.lv/security.nsf/dx/26032026145853VTAH8U.htm</guid><wfw:commentRss> http://update.cyone.lv/security.nsf/dxcomments/26032026145853VTAH8U.htm</wfw:commentRss><wfw:comment> http://update.cyone.lv/security.nsf/dx/26032026145853VTAH8U.htm?opendocument&amp;comments</wfw:comment></item>
<item><title>Security Bulletin: HCL Nomad for iOS is susceptible to a cookie overflow vulnerability in libcurl (CVE-2025-9086) Score: 7.5 (high) 🔥</title><pubDate>Thu, 26 Mar 2026 14:52:41 +0300</pubDate><description><![CDATA[ Summary HCL Nomad for iOS is susceptible to a cookie overflow vulnerability in libcurl. Vulnerability Details CVE-ID: CVE-2025-9086 Description: 1. A cookie is set using the `secure` keyword for `]]></description><link>http://update.cyone.lv/security.nsf/dx/26032026145241VTAH4Y.htm</link><dc:subject>Nomad</dc:subject><dc:creator>Vladislav Tatarincev</dc:creator><comments>http://update.cyone.lv/security.nsf/dx/26032026145241VTAH4Y.htm?opendocument&amp;comments</comments><guid isPermaLink="true">http://update.cyone.lv/security.nsf/dx/26032026145241VTAH4Y.htm</guid><wfw:commentRss> http://update.cyone.lv/security.nsf/dxcomments/26032026145241VTAH4Y.htm</wfw:commentRss><wfw:comment> http://update.cyone.lv/security.nsf/dx/26032026145241VTAH4Y.htm?opendocument&amp;comments</wfw:comment></item>
<item><title>Security Bulletin: HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage (CVE-2024-42192) Score: 5.5 (medium)</title><pubDate>Thu, 26 Mar 2026 14:51:39 +0300</pubDate><description><![CDATA[ Summary HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage vulnerability. Vulnerability Details CVE-ID: CVE-2024-42192 Description: HCL Traveler for Microsoft Outlook]]></description><link>http://update.cyone.lv/security.nsf/dx/26032026145139VTAH4B.htm</link><dc:subject>HTMO</dc:subject><dc:creator>Vladislav Tatarincev</dc:creator><comments>http://update.cyone.lv/security.nsf/dx/26032026145139VTAH4B.htm?opendocument&amp;comments</comments><guid isPermaLink="true">http://update.cyone.lv/security.nsf/dx/26032026145139VTAH4B.htm</guid><wfw:commentRss> http://update.cyone.lv/security.nsf/dxcomments/26032026145139VTAH4B.htm</wfw:commentRss><wfw:comment> http://update.cyone.lv/security.nsf/dx/26032026145139VTAH4B.htm?opendocument&amp;comments</wfw:comment></item>

</channel></rss>
