HCL DevOps Deploy / HCL Launch is susceptible to an insufficient session expiration vulnerability
Vulnerability Description
HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62329
Credits & Attribution
No credits recorded in the NVD database.
More from HCL Software
View All →Affected Vendor
HCL Software
View all reports →