Executive brief
HCL Traveler for Microsoft Outlook (HTMO), a tool that allows users to access HCL Domino mail and calendar data within the Outlook client, is vulnerable to sensitive data exposure. An attacker with local access to a user's computer could potentially view sensitive application information, which could be used to facilitate further attacks or cause the application to behave unexpectedly. This risk primarily impacts the confidentiality of user data stored or processed by the mail client.
Technical details
HCL Traveler for Microsoft Outlook (HTMO) versions prior to 3.0.15 are vulnerable to sensitive data exposure due to the insertion of sensitive information into log files (CWE-532). An attacker with local access and low privileges (AV:L/PR:L) can read these logs to extract application-specific information. This exposure of data can be leveraged to conduct further attacks or disrupt application stability. The vulnerability is addressed in HTMO version 3.0.15.
Affected products
- HCL Software Traveler for Microsoft Outlook (HTMO) < 3.0.15
Timeline
- 2026-06-26: advisory: HCL Software published the security bulletin KB0131419.
- 2026-06-27: disclosed: CVE-2025-59868 was published to the NVD.