CVE-2025-59849: Hcltechsw Hcl Devops Deploy
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
Affected products
- Hcltechsw Hcl Devops Deploy: from 8.0.0.0, before 8.0.1.11 (fixed in 8.0.1.11); from 8.1.0, before 8.1.2.4 (fixed in 8.1.2.4)
- Hcltechsw Hcl Launch: from 7.3.0.0, before 7.3.2.16 (fixed in 7.3.2.16)
Published 2025-12-17. Last modified 2026-09-30.