Hcltechsw
Hcltechsw HCL Devops Deploy: vulnerabilidades y CVE
Hcltechsw HCL Devops Deploy tiene 20 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses9
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-56460 | Media (6.5) | 0.38% | — | 9 jul 2026 | HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system. |
| CVE-2026-56459 | Media (5.5) | 0.15% | — | 9 jul 2026 | HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read by a local user. |
| CVE-2026-56458 | Alta (7.5) | 0.26% | — | 9 jul 2026 | HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted… |
| CVE-2026-56457 | Media (4.3) | 0.30% | — | 29 jun 2026 | HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values… |
| CVE-2025-62327 | Media (4.9) | 0.26% | — | 7 ene 2026 | In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries. |
| CVE-2025-55254 | Media (4.8) | 0.19% | — | 17 dic 2025 | Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow to execute malicious code in certain web pages. |
| CVE-2025-59849 | Media (6.1) | 0.19% | — | 17 dic 2025 | Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages. |
| CVE-2025-62329 | Media (5.6) | 0.19% | — | 16 dic 2025 | HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could… |
| CVE-2025-62330 | Media (5.9) | 0.15% | — | 16 dic 2025 | HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access… |
| CVE-2025-0272 | Alta (7.6) | 0.25% | — | 3 abr 2025 | HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. |
| CVE-2025-0257 | Alta (7.5) | 0.30% | — | 2 abr 2025 | HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service. |
| CVE-2025-0273 | Media (5.5) | 0.15% | — | 27 mar 2025 | HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user. |
| CVE-2025-0255 | Alta (7.2) | 0.68% | — | 24 mar 2025 | HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements. |
| CVE-2025-0256 | Media (6.5) | 0.27% | — | 24 mar 2025 | HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function. |
| CVE-2024-42195 | Media (6.8) | 0.29% | — | 5 dic 2024 | HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. |
| CVE-2024-23561 | Media (4.3) | 0.36% | — | 15 abr 2024 | HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values. |
| CVE-2024-23558 | Media (6.3) | 0.31% | — | 15 abr 2024 | HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. |
| CVE-2024-23560 | Media (4.9) | 0.32% | — | 15 abr 2024 | HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. |
| CVE-2024-23559 | Media (6.1) | 0.31% | — | 15 abr 2024 | HCL DevOps Deploy / Launch is generating an obsolete HTTP header. |
| CVE-2024-23550 | Media (5.5) | 0.21% | — | 3 feb 2024 | HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.