9 results (0.003 seconds)

CVSS: 6.2EPSS: 0%CPEs: 5EXPL: 0

HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent. HCL DevOps Deploy/HCL Launch (UCD) podría revelar información confidencial del usuario al instalar el agente de Windows. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0110334 •

CVSS: 6.5EPSS: 0%CPEs: 4EXPL: 0

HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. HCL Launch podría permitir a un atacante remoto obtener información confidencial cuando se devuelve un mensaje de error técnico detallado en el navegador. Esta información podría usarse en futuros ataques contra el sistema. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108645 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion. HCL Launch puede manejar mal la validación de entrada de un archivo cargado, lo que lleva a una denegación de servicio debido al agotamiento de los recursos. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108649 •

CVSS: 5.5EPSS: 0%CPEs: 5EXPL: 0

HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0105978 •

CVSS: 5.4EPSS: 0%CPEs: 5EXPL: 0

HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102081 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •