Vulnerability record · CVE-2025-62329 · published 16 December 2025
CVE-2025-62329: Hcltechsw hcl devops deploy insufficient session expiration vulnerability
Hcltechsw · Hcl Devops Deploy
HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.
Description
HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127332 | Vendor Advisory |
Track CVE-2025-62329 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-62329), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.