Hcltechsw
Hcltechsw HCL Launch: vulnerabilities and CVEs
Hcltechsw HCL Launch has 28 published vulnerabilities, 6 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs28
Last 12 months6
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56460 | Medium (6.5) | 0.38% | — | Jul 9, 2026 | HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system. |
| CVE-2026-56459 | Medium (5.5) | 0.15% | — | Jul 9, 2026 | HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read by a local user. |
| CVE-2026-56457 | Medium (4.3) | 0.30% | — | Jun 29, 2026 | HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values… |
| CVE-2025-55254 | Medium (4.8) | 0.19% | — | Dec 17, 2025 | Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow to execute malicious code in certain web pages. |
| CVE-2025-59849 | Medium (6.1) | 0.19% | — | Dec 17, 2025 | Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages. |
| CVE-2025-62329 | Medium (5.6) | 0.19% | — | Dec 16, 2025 | HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could… |
| CVE-2025-0272 | High (7.6) | 0.25% | — | Apr 3, 2025 | HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. |
| CVE-2025-0257 | High (7.5) | 0.30% | — | Apr 2, 2025 | HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service. |
| CVE-2025-0273 | Medium (5.5) | 0.15% | — | Mar 27, 2025 | HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user. |
| CVE-2025-0255 | High (7.2) | 0.68% | — | Mar 24, 2025 | HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements. |
| CVE-2025-0256 | Medium (6.5) | 0.27% | — | Mar 24, 2025 | HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function. |
| CVE-2024-42196 | Medium (5.5) | 0.15% | — | Dec 6, 2024 | HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs. |
| CVE-2024-42195 | Medium (6.8) | 0.29% | — | Dec 5, 2024 | HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. |
| CVE-2024-23561 | Medium (4.3) | 0.36% | — | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values. |
| CVE-2024-23558 | Medium (6.3) | 0.31% | — | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. |
| CVE-2024-23560 | Medium (4.9) | 0.32% | — | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. |
| CVE-2024-23559 | Medium (6.1) | 0.31% | — | Apr 15, 2024 | HCL DevOps Deploy / Launch is generating an obsolete HTTP header. |
| CVE-2024-23550 | Medium (5.5) | 0.21% | — | Feb 3, 2024 | HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent. |
| CVE-2023-45702 | Medium (5.5) | 0.16% | — | Dec 28, 2023 | An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts.. |
| CVE-2023-45701 | Medium (6.5) | 0.48% | — | Dec 28, 2023 | HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. |
| CVE-2023-45700 | Medium (5.4) | 0.31% | — | Dec 21, 2023 | HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. |
| CVE-2023-45703 | High (7.5) | 0.46% | — | Dec 21, 2023 | HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion. |
| CVE-2023-23348 | Medium (5.5) | 0.15% | — | Jul 10, 2023 | HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed. |
| CVE-2022-42452 | Medium (5.4) | 0.34% | — | Apr 2, 2023 | HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections. |
| CVE-2022-42445 | Medium (4.9) | 0.58% | — | Dec 12, 2022 | HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches. |
| CVE-2022-27551 | Medium (6.5) | 0.53% | — | Aug 3, 2022 | HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking. |
| CVE-2022-27549 | Medium (5.5) | 0.15% | — | Jul 6, 2022 | HCL Launch may store certain data for recurring activities in a plain text format. |
| CVE-2022-27548 | Medium (5.5) | 0.51% | — | Jul 6, 2022 | HCL Launch stores user credentials in plain clear text which can be read by a local user. |