HCLSoftware Vulnerabilities and Affected Products
Vulnerabilities associated with HCL DevOps Deploy / HCL Launch.
Products
Clear product- Aftermarket EPC14 vulnerabilities
- MyCloud7 vulnerabilities
- Connections6 vulnerabilities
- DevOps Loop4 vulnerabilities
- IntelliOps Event Management4 vulnerabilities
- BigFix IVR3 vulnerabilities
- HCL DevOps Deploy / HCL Launch3 vulnerabilities
- Traveler for Microsoft Outlook3 vulnerabilities
- BigFix Platform2 vulnerabilities
- BigFix Service Management (SM)2 vulnerabilities
- BigFix WebUI2 vulnerabilities
- DevOps Plan2 vulnerabilities
- DFXServer2 vulnerabilities
- Digital Experience2 vulnerabilities
- HCL BigFix Mobile2 vulnerabilities
- Traveler2 vulnerabilities
- BigFix Cloud Lifecycle Management1 vulnerability
- BigFix Compliance1 vulnerability
- BigFix Remote Control Server1 vulnerability
- BigFix SCM Reporting1 vulnerability
- Commerce1 vulnerability
- DevOps Deploy1 vulnerability
- DFMPro for CATIA1 vulnerability
- DFXAnalytics1 vulnerability
- Digital Experience & DX Compose1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-56460MEDIUM | HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerabilityHCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system. CWE-201Jul 9, 2026 | CVSS6.5v3.1 | EPSS0.224% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-56459MEDIUM | HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosureHCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read by a local user. CWE-532Jul 9, 2026 | CVSS6.2v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-56457MEDIUM | HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive informationHCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step. CWE-532Jun 29, 2026 | CVSS4.3v3.1 | EPSS0.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |