- 
                  Products    
                  - Business & Industry Applications
- Cybersecurity
- Data and Analytics
- AI and Intelligent Operations
- Total Experience
- Sovereign Collaboration
- Specialized Software
 - HCL Aftermarket Cloud Aftermarket-led growth platform
- HCL Automation Orchestration Streamline Business Processes
- HCL Commerce+ Enterprise e-commerce for B2C and B2B
- HCL CDP Flexible and customizable customer data platform
- HCL Discover+ Behavioral insights for customer journeys
- HCL Marketing Cloud Fueling precision marketing at scale with AI
- HCL Unica Enterprise marketing automation platform
 - HCL AppScan Scans for application vulnerabilities
- HCL BigFix Secure endpoint management
- HCL BigFix Compliance Ensure security with continuous, real-time compliance monitoring
- HCL BigFix CyberFOCUS Supercharging IT operations to secure the enterprise
- HCL BigFix Remediate Automate, remediate & secure endpoints
 - HCL Actian Empowers the data-driven enterprise
- HCL Actian Data Platform Data services suite; flexible deployment
- HCL Actian Ingres Legendary transactional RDBMS
- HCL DataConnect Low-code integration platform
- HCL Zeenea Data Intelligence Platform Cloud-native data governance solution
- HCL Zen Embeddable edge data management
 - HCL Automation Orchestration Streamline Business Processes
- HCL Automation Orchestrator Suite Accelerate IT and business automation
- HCL BigFix Secure endpoint management
- HCL BigFix AEX AI-driven employee experience accelerating productivity and innovation
- HCL BigFix Enterprise+ An all-in-one IT infrastructure automation offering enabling you to stay ahead of cyber threats
- HCL BigFix Service Management AI-powered Service Management for IT and beyond
- HCL BigFix Workspace+ Fueling GenAI within the Digital+ experience
- HCL iControl HCL iControl is a business flow and process observability solution
- HCL MyXalytics Cloud finOps visibility and insights
- HCL Workload Automation Simplify and automation business workflows
 - HCL Automation Orchestration Streamline Business Processes
- HCL CDP Flexible and customizable customer data platform
- HCL DX The DXP for the moments that matter
- HCL Foundry Secure backend services
- HCL TX Platform Deliver seamless customer and employee experiences
- HCL Volt MX Multi-experience low code app dev
 - HCL Connections Collaboration and task management in one workspace
- HCL Domino Rapid application development platform
- HCL Link Connectivity across your digital ecosystem
- HCL Notes Comprehensive email and collaboration hub
- HCL SafeLinx Secure and flexible remote access to enterprise applications
- HCL Sametime Secure meetings, video, and chat communications
- HCL Verse Smart and secure enterprise email for seamless workflow
 - HCL Augmented Network Automation (SON)Intelligent RAN automation platform
- HCL DFMProCAD integrated Design-for-Manufacturing platform
- HCL CAMWorksCAM for machining productivity
- HCL GloviusModern lightweight CAD Viewer
- HCL Mainframe Optimization Optimize, modernize, and innovate your mainframe investments
- HCL Secure DevOps Automated testing and security scanning
 - Artificial Intelligence: Built for Scale Humanizing artificial intelligence to elevate IT Operations
 - HCL Actian Data Platform Data services suite; flexible deployment
- HCL AION AI life cycle management platform
- HCL AppScan Scans for application vulnerabilities
- HCL BigFix Secure endpoint management
- HCL Commerce+ Enterprise e-commerce for B2C and B2B
- HCL Domino Rapid application development platform
- HCL iAutomate Accelerating IT operations with intelligent, end-to-end automation
- HCL iControl HCL iControl is a business flow and process observability solution
- HCL MyXalytics Cloud finOps visibility and insights
- HCL Secure DevOps Automated testing and security scanning
- HCL TX Platform Deliver seamless customer and employee experiences
- HCL Unica Enterprise marketing automation platform
- HCL Volt MX Multi-experience low code app dev
- HCL Zeenea Data Intelligence Platform Cloud-native data governance solution
 - HCL Actian
- HCL Actian Data Platform
- HCL Actian Ingres
- HCL Aftermarket Cloud
- HCL AION
- HCL AppScan
- HCL Automation Orchestration
- HCL Automation Orchestrator Suite
- HCL BigFix
- HCL CAMWorks
- HCL Clara
- HCL Commerce+
- HCL Connections
- HCL Customer Data Platform
- HCL DataConnect
- HCL DFMPro
- HCL Discover+
- HCL Domino
- HCL DX
- HCL DevOps Code ClearCase
- HCL DevOps Code RealTime
- HCL DevOps Deploy
- HCL DevOps Plan
- HCL DevOps Model RealTime
- HCL DevOps Test
- HCL DevOps Test Embedded
- HCL DevOps Velocity
- HCL Glovius
- HCL Hero
- HCL HIVE
- HCL iAutomate
- HCL iControl
- HCL Informix
- HCL IntelliOps
- HCL IntelliOps Event Management
- HCL iObserve
- HCL Link
- HCL Mainframe Solutions
- HCL Marketing Cloud
- HCL Marketplace
- HCL MyXalytics
- HCL MyXalytics Finops
- HCL Nippon
- HCL Notes
- HCL Now
- HCL SafeLinx
- HCL Sametime
- HCL Secure DevOps
- HCL TX Platform
- HCL Unica
- HCL Universal Orchestrator
- HCL Vector Analytics
- HCL Verse
- HCL Volt MX
- HCL Workload Automation
- HCL Z Asset Optimizer
- HCL Z Abend Investigator
- HCL Z and I Emulator
- HCL Zeenea Data Intelligence Platform
- HCL Zen Edge Data Management
 - Citizen Developers
- IT Operations & Management
- Line of Business
- Data Analysts
- Security & IT Compliance
 - HCL AppScan Scans for Application Vulnerabilities
- HCL DataConnect Low-code integration platform
- HCL Domino Rapid application development platform
- HCL Secure DevOps Automated testing and security scanning
- HCL TX Platform Deliver seamless customer and employee experiences
- HCL Volt MX Multi-experience low code app dev
 - HCL Automation Orchestrator Suite Accelerate IT and business automation
- HCL BigFix Workspace+ Fueling GenAI within the Digital+ experience
- HCL BigFix Service Management AI-powered Service Management for IT and beyond
- HCL BigFix AEX AI-driven employee experience accelerating productivity and innovation
- HCL iControl HCL iControl is a business flow and process observability solution
- HCL MyXalytics Cloud finOps visibility and insights
- HCL Workload Automation Simplify and automation business workflows
 - HCL Aftermarket Cloud Aftermarket-led growth platform
- HCL Automation Orchestrator Suite Accelerate IT and business automation
- HCL Augmented Network Automation (SON)Intelligent RAN automation platform
- HCL Commerce+ Enterprise e-commerce for B2C and B2B
- HCL CAMWorksCAM for machining productivity
- HCL CDP Flexible and customizable customer data platform
- HCL DFMProCAD integrated Design-for-Manufacturing platform
- HCL Discover+ Behavioral insights for customer journeys
- HCL GloviusModern lightweight CAD Viewer
- HCL Marketing Cloud Fueling Precision Marketing At Scale with AI
- HCL Unica Enterprise marketing automation platform
 - HCL Actian Empowers the data-driven enterprise
- HCL Actian Data Platform Data services suite; flexible deployment
- HCL Actian Ingres Legendary transactional RDBMS
- HCL CDP Flexible and customizable customer data platform
- HCL DataConnect Low-code integration platform
- HCL Zeenea Data Intelligence Platform Cloud-native data governance solution
- HCL Zen Embeddable edge data management
 - HCL AppScan Scans for Application Vulnerabilities
- HCL BigFix Secure endpoint management
- HCL BigFix Compliance Ensure security with continuous, real-time compliance monitoring
- HCL BigFix CyberFOCUS Supercharging IT operations to secure the enterprise
- HCL BigFix Remediate Automate, remediate & secure endpoints
- HCL Secure DevOps Automated testing and security scanning
 
- Industries
- Partners
- Customer Success
- What We Envision
HCLSoftware Product Security Incident Response
 
       
  
     
            HCLSoftware PSIRT
HCLSoftware is committed to the safety and security of all our products and services. The HCLSoftware Product Security Incident Response Team (PSIRT) has been commissioned to manage the investigation and remediation of security vulnerabilities related to HCLSoftware offerings. This page describes our policy and process for handling security vulnerabilities in our products.
Report a Security Vulnerability
 
                            
                            
                    Report a Security Vulnerability
To report a suspected security vulnerability to HCLSoftware, send an email to PSIRT@hcl-software.com. When submitting your report, be sure to include the product name, version, summary of the suspected security vulnerability, security impact of the vulnerability, and steps to reproduce the issue.
Please refer to our HCLSoftware Vulnerability Disclosure Policy prior to making your submission to ensure that you are reporting on In-scope software, reporting through the proper channels, and aware of our legal terms.
Analysis and Remediation
Acknowledgment and Analysis of a Vulnerability Report
If you submitted a vulnerability report via PSIRT@hcl-software.com, HCLSoftware Product Security will acknowledge the receipt of the report within 2 business days. A tracking number will be provided in the acknowledgment email. Please include this tracking number in the subject of all further email communications relating to the submission.
Vulnerability Remediation
For all validated security vulnerabilities affecting HCLSoftware products and services that are in active support, HCLSoftware will provide a fix or workaround. A Security Bulletin describing the fix or workaround will be posted in the Knowledge Base on the HCL Customer Support portal.
Severity Rating
HCLSoftware uses version 3.1 of the Common Vulnerability Scoring System (CVSS) as part of its standard process of evaluating reported potential vulnerabilities in HCLSoftware products. The CVSS model uses three distinct measurements or scores that include Base, Temporal, and Environmental calculations.
HCLSoftware will provide an evaluation of the base vulnerability score, and in some instances, will provide a temporal vulnerability score. End users are encouraged to compute the environmental score based on their network parameters. The combination of all three scores should be considered the final score, which represents a moment in time and is tailored to a specific environment. Organizations are advised to use this final score to prioritize responses in their own environments.
Security Bulletins
        
Advisories or Bulletins of Product Security Information and Software Updates 
Information relating to addressed vulnerabilities are published in Security Advisories or Security Bulletins, which are available from the Knowledge Base on the HCL Customer Support portal.” You can sign up for push notifications via email for the security bulletins you care about by visiting the HCL PSIRT Blog and subscribing to one or more of the Topics on the right hand side of the page.  You can also search the HCL Support Knowledge Base for security bulletins."
Security bulletins are published under the following situations:
  - A security issue that is specific to our software or that affects open-source software that can reasonably be assumed to affect our software is publicly reported and widely available; AND a fix is available in one or more supported software versions.
- A security issue that affects our software is privately reported to HCLSoftware; and a fix is available in currently supported software versions.
Security bulletins will include the following information, where applicable:
  - Affected products and versions
- Description of vulnerability
- Potential impact rating
- Common Vulnerability Enumerator ID (CVE: http://www.cve.org )
- Severity rating (HCL uses version 3.1 of the Common Vulnerability Scoring System, CVSSv3.1; https://www.first.org/cvss/user-guide)
- Available updates, fixes or workarounds
- Acknowledgement of the reporter (if applicable)
Industry Affiliations
 Advisories or Bulletins of Product Security Information and Software Updates 
Information relating to addressed vulnerabilities are published in Security Advisories or Security Bulletins, which are available from the Knowledge Base on the HCL Customer Support portal.” You can sign up for push notifications via email for the security bulletins you care about by visiting the HCL PSIRT Blog and subscribing to one or more of the Topics on the right hand side of the page.  You can also search the HCL Support Knowledge Base for security bulletins."
Security bulletins are published under the following situations:
- A security issue that is specific to our software or that affects open-source software that can reasonably be assumed to affect our software is publicly reported and widely available; AND a fix is available in one or more supported software versions.
- A security issue that affects our software is privately reported to HCLSoftware; and a fix is available in currently supported software versions.
Security bulletins will include the following information, where applicable:
- Affected products and versions
- Description of vulnerability
- Potential impact rating
- Common Vulnerability Enumerator ID (CVE: http://www.cve.org )
- Severity rating (HCL uses version 3.1 of the Common Vulnerability Scoring System, CVSSv3.1; https://www.first.org/cvss/user-guide)
- Available updates, fixes or workarounds
- Acknowledgement of the reporter (if applicable)
Industry Affiliations