Missing Authentication in HCL DevOps Deploy and HCL Launch Agent Relay Service
CVE-2025-0257
6.3MEDIUM
Key Information:
- Vendor
- HCL Software Software
- Status
- HCL Software Devops Deploy / HCL Software Launch
- Vendor
- CVE Published:
- 2 April 2025
Summary
The Agent Relay service within HCL DevOps Deploy and HCL Launch is susceptible to a security flaw where missing authentication mechanisms could permit unauthorized access. This vulnerability poses a risk by potentially exposing sensitive data and allowing improper interactions with other services. Organizations using these tools should evaluate their exposure and consider remediation actions promptly to protect their infrastructure.
Affected Version(s)
HCL DevOps Deploy / HCL Launch 7.1 - 7.1.2.22; 7.2 - 7.2.3.15; 7.3 - 7.3.2.10; 8.0 - 8.0.1.5; 8.1 - 8.1.0.1
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved