11 results (0.006 seconds)

CVSS: 6.2EPSS: 0%CPEs: 5EXPL: 0

03 Feb 2024 — HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent. HCL DevOps Deploy/HCL Launch (UCD) podría revelar información confidencial del usuario al instalar el agente de Windows. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0110334 •

CVSS: 6.2EPSS: 0%CPEs: 3EXPL: 0

28 Dec 2023 — An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts.. Un agente de implementación HCL UrbanCode instalado como un servicio de Windows en una ubicación no estándar podría estar sujeto a un ataque de denegación de servicio por parte de cuentas locales. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108646 •

CVSS: 6.8EPSS: 0%CPEs: 4EXPL: 0

28 Dec 2023 — HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. HCL Launch podría permitir a un atacante remoto obtener información confidencial cuando se devuelve un mensaje de error técnico detallado en el navegador. Esta información podría usarse en futuros ataques contra el sistema. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108645 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVSS: 5.5EPSS: 0%CPEs: 3EXPL: 0

21 Dec 2023 — HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. HCL Launch es vulnerable a la inyección de HTML. Esta vulnerabilidad puede permitir que un usuario incruste etiquetas HTML arbitrarias en la interfaz de usuario web, lo que podría provocar la divulgación de información confidencial. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108644 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

20 Dec 2023 — HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion. HCL Launch puede manejar mal la validación de entrada de un archivo cargado, lo que lleva a una denegación de servicio debido al agotamiento de los recursos. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108649 •

CVSS: 5.5EPSS: 0%CPEs: 5EXPL: 0

10 Jul 2023 — HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0105978 • CWE-922: Insecure Storage of Sensitive Information •

CVSS: 5.5EPSS: 0%CPEs: 5EXPL: 0

30 Mar 2023 — HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102081 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 4EXPL: 0

28 Nov 2022 — HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches. HCL Launch podría permitir a un usuario con privilegios administrativos, incluidos permisos de "Administrar seguridad", la capacidad de recuperar una credencial previamente guardada para realizar búsquedas LDAP autenticadas. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0101208 •

CVSS: 6.8EPSS: 0%CPEs: 3EXPL: 0

03 Aug 2022 — HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking. HCL Launch podría permitir a un usuario autenticado obtener información confidencial en algunos casos debido a una comprobación de seguridad inapropiada • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0099732 • CWE-863: Incorrect Authorization •

CVSS: 5.5EPSS: 0%CPEs: 3EXPL: 0

06 Jul 2022 — HCL Launch may store certain data for recurring activities in a plain text format. HCL Launch puede almacenar determinados datos para actividades recurrentes en un formato de texto plano • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0099254 • CWE-312: Cleartext Storage of Sensitive Information CWE-532: Insertion of Sensitive Information into Log File •