Loading HuntDB...

HCL Launch

9 Versions 11 CVEs

Recent CVEs

CVE-2023-45702

An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts..

MEDIUM Dec 28, 2023

CVE-2023-45701

HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

MEDIUM Dec 28, 2023

CVE-2023-45700

HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

MEDIUM Dec 21, 2023

CVE-2023-45703

HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion.

MEDIUM Dec 20, 2023

CVE-2023-23348

HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.

MEDIUM Jul 10, 2023

CVE-2022-42452

HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.

MEDIUM Mar 30, 2023

CVE-2022-42445

HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.

MEDIUM Nov 28, 2022

CVE-2021-27784

The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.

MEDIUM Oct 31, 2022