Missing Authentication in HCL DevOps Deploy and HCL Launch Agent Relay Service
CVE-2025-0257

6.3MEDIUM

Key Information:

Vendor
HCL Software Software
Status
HCL Software Devops Deploy / HCL Software Launch
Vendor
CVE Published:
2 April 2025

Summary

The Agent Relay service within HCL DevOps Deploy and HCL Launch is susceptible to a security flaw where missing authentication mechanisms could permit unauthorized access. This vulnerability poses a risk by potentially exposing sensitive data and allowing improper interactions with other services. Organizations using these tools should evaluate their exposure and consider remediation actions promptly to protect their infrastructure.

Affected Version(s)

HCL DevOps Deploy / HCL Launch 7.1 - 7.1.2.22; 7.2 - 7.2.3.15; 7.3 - 7.3.2.10; 8.0 - 8.0.1.5; 8.1 - 8.1.0.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.