Impact
HCL DevOps Loop contains a forced‑browsing flaw that allows attackers to bypass the product’s authorization checks and directly access administrative operations by simply navigating to protected URLs. The vulnerability permits an unauthenticated user to view or alter sensitive administrative settings, potentially exposing configuration data and disrupting service operation. The flaw is classified as a CWE‑425 weakness in directly accessing protected resources, and its CVSS score of 4.6 reflects a moderate impact on security.
Affected Systems
The affected product is HCL Software DevOps Loop. No specific version numbers are supplied in the advisory, so every deployment of this product is considered at risk until a vendor release that addresses the weakness is confirmed. Organizations running any version of DevOps Loop should treat the system as vulnerable and apply controls until they can verify patch availability.
Risk and Exploitability
The EPSS score of less than 1% indicates a low likelihood that this vulnerability will be exploited in the near term, and the flaw is not listed in the CISA KEV catalog. The most probable attack is straightforward forced‑browsing of the application’s admin URLs; an attacker with no authentication can manually try known endpoint paths. Although the exploitation cost is low, the potential impact on confidentiality, integrity and availability of configuration information warrants monitoring and mitigation.
OpenCVE Enrichment