HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related data via passive monitoring or man-in-the-middle attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related data via passive monitoring or man-in-the-middle attacks. | |
| Title | HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information | |
| Weaknesses | CWE-319 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2025-12-16T06:16:09.877Z
Reserved: 2025-10-10T09:04:23.571Z
Link: CVE-2025-62330
No data.
Status : Received
Published: 2025-12-16T07:15:53.457
Modified: 2025-12-16T07:15:53.457
Link: CVE-2025-62330
No data.
OpenCVE Enrichment
No data.