Vulnerabilities
Vulnerable Software
HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.
CVSS Score
6.2
EPSS Score
0.0
Published
2024-02-03
HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
CVSS Score
4.3
EPSS Score
0.001
Published
2023-12-28
HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion.
CVSS Score
5.3
EPSS Score
0.001
Published
2023-12-21
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.
CVSS Score
5.1
EPSS Score
0.001
Published
2023-07-10
HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
CVSS Score
4.6
EPSS Score
0.003
Published
2023-04-02
HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.
CVSS Score
4.9
EPSS Score
0.001
Published
2022-12-12
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
CVSS Score
5.3
EPSS Score
0.002
Published
2022-08-03
HCL Launch stores user credentials in plain clear text which can be read by a local user.
CVSS Score
4.9
EPSS Score
0.001
Published
2022-07-06
HCL Launch may store certain data for recurring activities in a plain text format.
CVSS Score
4.0
EPSS Score
0.0
Published
2022-07-06


Contact Us

Shodan ® - All rights reserved