← Back

Hcl Launch

hcl_launch

Vendor: Hcltechsw • 28 CVEs

CVEs (28)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltechsw
1Hcl Launch
Jun 17, 2026
Dec 21, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
1Hcltechsw
1Hcl Launch
Jun 17, 2026
Dec 21, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion.
1Hcltechsw
1Hcl Launch
Jun 17, 2026
Jul 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.
1Hcltechsw
1Hcl Launch
Jun 17, 2026
Apr 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections.
1Hcltechsw
1Hcl Launch
Jun 17, 2026
Dec 12, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.
1Hcltechsw
1Hcl Launch
Jun 17, 2026
Aug 3, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
1Hcltechsw
1Hcl Launch
Jun 17, 2026
Jul 6, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
HCL Launch may store certain data for recurring activities in a plain text format.
1Hcltechsw
1Hcl Launch
Jun 17, 2026
Jul 6, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
HCL Launch stores user credentials in plain clear text which can be read by a local user.