HCL SOFTWARE HCL Launch 7.2.3.3

CPE Details

HCL SOFTWARE HCL Launch 7.2.3.3
7.2.3.3
2023-04-05
14h28 +00:00
2023-04-07
13h29 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:hcltechsw:hcl_launch:7.2.3.3:*:*:*:*:*:*:*

Informations

Vendor

hcltechsw

Product

hcl_launch

Version

7.2.3.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-0272 2025-04-03 14h56 +00:00 HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
7.6
High
CVE-2025-0257 2025-04-02 22h04 +00:00 HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.
7.5
High
CVE-2025-0273 2025-03-27 05h03 +00:00 HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.
5.5
Medium
CVE-2025-0255 2025-03-24 16h32 +00:00 HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
7.2
High
CVE-2025-0256 2025-03-24 15h35 +00:00 HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
6.5
Medium
CVE-2024-42196 2024-12-06 14h47 +00:00 HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
6.2
Medium
CVE-2024-23558 2024-04-15 21h00 +00:00 HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
6.3
Medium
CVE-2024-23561 2024-04-15 20h20 +00:00 HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.
4.3
Medium
CVE-2024-23560 2024-04-15 19h22 +00:00 HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.
4.9
Medium
CVE-2024-23559 2024-04-15 17h31 +00:00 HCL DevOps Deploy / Launch is generating an obsolete HTTP header.
6.1
Medium
CVE-2024-23550 2024-02-03 05h32 +00:00 HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.
6.2
Medium
CVE-2023-45702 2023-12-28 07h29 +00:00 An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts..
6.2
Medium
CVE-2023-45701 2023-12-28 07h03 +00:00 HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
6.5
Medium
CVE-2023-45700 2023-12-21 00h10 +00:00 HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
5.4
Medium
CVE-2023-45703 2023-12-20 23h33 +00:00 HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion.
7.5
High
CVE-2023-23348 2023-07-10 17h06 +00:00 HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.
5.5
Medium