HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers.
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131041