📦

dryice_iautomate

Vendor: hcltech

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 11 Total Indexed
Avg. EPSS 0.24% Exploit Prob.
Latest CVE CVE-2025-31954 Nov 05

Security Vulnerability Index

Page 1 / 2
5.4 CVSS

HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.

EPSS: 0.18%
7.6 CVSS

HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system.

EPSS: 0.29%
7.1 CVSS

HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.

EPSS: 0.26%
7.1 CVSS

HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.

EPSS: 0.33%
5.5 CVSS

HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.

EPSS: 0.28%
6.4 CVSS

HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.

EPSS: 0.11%