Impact
The vulnerability in HCL DevOps Plan is an information disclosure flaw that can expose sensitive data, categorised as CWE‑497. An attacker who successfully exploits it may obtain confidential information that could be leveraged to plan or execute follow‑up attacks. The description does not indicate direct compromise of confidentiality, integrity, or availability beyond the leakage of information.
Affected Systems
HCLSoftware’s DevOps Plan is the affected product. Specific version details are not provided, so the flaw may impact all releases until a vendor fix is deployed.
Risk and Exploitability
The CVSS score of 6.9 signals moderate severity, but the EPSS score of less than 1% indicates a low probability that the vulnerability will be actively exploited. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is that a 3rd‑party with network access to the DevOps Plan could trigger the disclosure by accessing an exposed endpoint or configuration page, revealing data that can aid downstream attacks.
OpenCVE Enrichment