Hcltech Devops Velocity — known CVE vulnerabilities
Every CVE whose affected-product data names Hcltech Devops Velocity, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (4)
CVE-2025-31991 — CVSS 6.8 (medium): Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks…
CVE-2024-22347 — CVSS 5.9 (medium): IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could…
CVE-2024-22348 — CVSS 5.3 (medium): IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an…
CVE-2024-22349 — CVSS 4.0 (medium): IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by…