CVE-2025-0257: HCL DevOps Deploy / HCL Launch is susceptible to unauthorized access to other services
Published Apr 2, 2025
·Updated
HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.
Affected Software
7 affected components
HCL DevOps Deploy
HCL Launch
Hcltechsw Hcl Devops Deploy>=8.0.0.0<8.0.1.6
Hcltechsw Hcl Devops Deploy>=8.1.0<8.1.1
Hcltechsw Hcl Launch>=7.1.0.0<7.1.2.23
Hcltechsw Hcl Launch>=7.2.0.0<7.2.3.16
Hcltechsw Hcl Launch>=7.3.0.0<7.3.2.11
Event History
Apr 2, 2025
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-0257?
CVE-2025-0257 is classified as a high severity vulnerability due to potential unauthorized access and data exposure.
2
How do I fix CVE-2025-0257?
To fix CVE-2025-0257, ensure that proper authentication mechanisms are implemented in the Agent Relay service.
3
What services are affected by CVE-2025-0257?
CVE-2025-0257 affects HCL DevOps Deploy and HCL Launch.
4
What type of vulnerability is CVE-2025-0257?
CVE-2025-0257 is an authentication vulnerability that allows unauthorized access to services.
5
What could be the consequences of CVE-2025-0257?
The consequences of CVE-2025-0257 may include unauthorized access to other services and the potential exposure of sensitive data.