HCL DevOps Deploy and HCL Launch Agent Relay Service Authentication Vulnerability Allowing Unauthorized Access and Data Exposure

Vulnerability

A vulnerability exists in the Agent Relay service of HCL DevOps Deploy and HCL Launch, versions 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, 7.3 through 7.3.2.10, 8.0 through 8.0.1.5, and 8.1 through 8.1.0.1. This vulnerability could lead to unauthorized access to other services or the potential exposure of sensitive data, due to missing authentication in the Agent Relay service.

Impact

Exploitation of this vulnerability could result in unauthorized access to services or exposure of sensitive data.

Remediation

Users are advised to upgrade to version 7.1.2.23, 7.2.3.16, 7.3.2.11, 8.0.1.6, or 8.1.1.0. These versions are available from the HCL Software License and Download Portal.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
5.0
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.