CVE-2025-62330Medium· 5.9▾ SunlitHCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or m…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related data via passive monitoring or man-in-the-middle attacks.
hcl_devops_deploy >= 8.1.0, < 8.1.2.4Upgrade past the affected range:
hcl_devops_deploy 8.1.2.4Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59849Medium· 4.7Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
CVE-2025-62327Medium· 4.9In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries.
CVE-2026-56460Medium· 6.5HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
CVE-2026-56457Medium· 4.3HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs
CVE-2026-107231High· 8.7AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic and sends the password in cleartext
CVE-2026-107232High· 7.5AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects the CONNECT