Skip to main content

Vendor archive

hcltechsw CVEs

Beta · best-effort

51 CVEs tagged to vendor hcltechsw3 Critical, 6 High, 38 Medium, 4 Low, 0 Unrated.

CVE-2026-56460

Published Jul 9, 2026

HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56459

Published Jul 9, 2026

HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure.  The application stores potentially sensitive information in log files that could be read by a l…

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56458

Published Jul 9, 2026

HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56457

Published Jun 29, 2026

HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs t…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62327

Published Jan 7, 2026

In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Querie…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62330

Published Dec 16, 2025

HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a re…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0257

Published Apr 2, 2025

HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0255

Published Mar 24, 2025

HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing spe…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-42196

Published Dec 6, 2024

HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23576

Published May 14, 2024

Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37522

Published Jan 16, 2024

HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 51 CVEsPage 1 of 3