Skip to main content

Vendor/product archive

hcltechsw / hcl_launch CVEs

Beta · best-effort

28 CVEs tagged to hcltechsw / hcl_launch0 Critical, 1 High, 25 Medium, 2 Low, 0 Unrated.

CVE-2026-56460

Published Jul 9, 2026

HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56459

Published Jul 9, 2026

HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure.  The application stores potentially sensitive information in log files that could be read by a l…

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56457

Published Jun 29, 2026

HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs t…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0257

Published Apr 2, 2025

HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0255

Published Mar 24, 2025

HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing spe…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-42196

Published Dec 6, 2024

HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45702

Published Dec 28, 2023

An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts..

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45701

Published Dec 28, 2023

HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in furt…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45700

Published Dec 21, 2023

HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45703

Published Dec 21, 2023

HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23348

Published Jul 10, 2023

HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42452

Published Apr 2, 2023

HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42445

Published Dec 12, 2022

HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenti…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 28 CVEsPage 1 of 2