HCL DevOps Deploy
cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*
- >= 8.1, <= 8.1.2.3
A vulnerability exists in HCL DevOps Deploy versions 8.1 prior to 8.1.2.3, allowing for cleartext transmission of sensitive information. The HTTP port remains accessible without proper redirection to HTTPS, enabling attackers with network access to intercept or modify user credentials and session data. This vulnerability could be exploited through passive monitoring or man-in-the-middle attacks.
Exploitation of this vulnerability could lead to interception or modification of user credentials and session-related data.
Users are advised to upgrade to version 8.1.2.4, 8.2.0.0 or later. These versions are available through the My HCLSoftware Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.