Description
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
Published: 2026-07-21
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in HCL DevOps Plan is an information disclosure flaw that can expose sensitive data, categorised as CWE‑497. An attacker who successfully exploits it may obtain confidential information that could be leveraged to plan or execute follow‑up attacks. The description does not indicate direct compromise of confidentiality, integrity, or availability beyond the leakage of information.

Affected Systems

HCLSoftware’s DevOps Plan is the affected product. Specific version details are not provided, so the flaw may impact all releases until a vendor fix is deployed.

Risk and Exploitability

The CVSS score of 6.9 signals moderate severity, but the EPSS score of less than 1% indicates a low probability that the vulnerability will be actively exploited. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is that a 3rd‑party with network access to the DevOps Plan could trigger the disclosure by accessing an exposed endpoint or configuration page, revealing data that can aid downstream attacks.

Generated by OpenCVE AI on August 1, 2026 at 07:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HCLDevOps Plan update or vendor‑issued patch that addresses the disclosure
  • Restrict network access to the DevOps Plan by enforcing least privilege and firewall rules so that only authorised personnel can reach sensitive endpoints
  • Disable or secure any configuration endpoints or APIs that expose data, and audit logs for abnormal read attempts

Generated by OpenCVE AI on August 1, 2026 at 07:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware devops Plan
Vendors & Products Hclsoftware
Hclsoftware devops Plan

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Description HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
Title An information disclosure vulnerability affects HCL DevOps Plan
Weaknesses CWE-497
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Hclsoftware Devops Plan
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-21T15:02:40.439Z

Reserved: 2023-07-06T16:11:40.095Z

Link: CVE-2023-37507

cve-icon Vulnrichment

Updated: 2026-07-21T15:02:25.968Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T07:15:03Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere