Executive brief
HCL ZIE for Web, a terminal emulation software for accessing host applications via a browser, is affected by a security flaw that allows users to upload unauthorized files. If the server is configured to execute scripts, an attacker could upload a malicious file to take control of the server or run unauthorized commands. This could lead to a full system compromise, data theft, or disruption of business operations.
Technical details
HCL ZIE for Web version 16.0 contains an unrestricted file upload vulnerability. An authenticated attacker with low privileges can upload files to the webroot. If the underlying server environment is configured to execute code (such as JSP or other server-side scripts), the attacker can upload a web shell to execute arbitrary operating system commands. While the vendor-provided CVSS score is 4.3 (indicating low impact on confidentiality), the description suggests a potential for full remote code execution (RCE) depending on server configuration. The vulnerability is tracked as CVE-2025-59872.
Affected products
- HCL Software ZIE for Web 16.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory