Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2024-23550

Disclosure Date: February 03, 2024 (last updated February 13, 2024)
HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.
Attacker Value
Unknown

CVE-2023-45702

Disclosure Date: December 28, 2023 (last updated January 05, 2024)
An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts..
Attacker Value
Unknown

CVE-2023-45701

Disclosure Date: December 28, 2023 (last updated January 05, 2024)
HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2023-45700

Disclosure Date: December 21, 2023 (last updated January 03, 2024)
HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
Attacker Value
Unknown

CVE-2023-45703

Disclosure Date: December 21, 2023 (last updated January 03, 2024)
HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion.
Attacker Value
Unknown

CVE-2023-23348

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.
Attacker Value
Unknown

CVE-2022-42452

Disclosure Date: April 02, 2023 (last updated November 08, 2023)
HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
Attacker Value
Unknown

CVE-2022-42445

Disclosure Date: December 12, 2022 (last updated November 08, 2023)
HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.
Attacker Value
Unknown

CVE-2021-27784

Disclosure Date: October 19, 2022 (last updated December 22, 2024)
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.
Attacker Value
Unknown

CVE-2022-27551

Disclosure Date: August 01, 2022 (last updated October 08, 2023)
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.