Junglewise Threat Intelligence

CVE-2025-63402: HCL Technologies Dragon remote code execution in APIs

CVE-2025-63402 · Severity: medium · CVSS 5.5 · Published 2025-12-03

Executive brief

HCLTech Dragon, a technology platform used for enterprise digital transformation, contains a security vulnerability in its application programming interfaces (APIs). An attacker with high-level access could exploit a lack of resource limits to execute unauthorized code on the system. This could lead to partial data exposure or disruption of business operations.

Technical details

A resource management vulnerability (CWE-770) exists in HCLTech Dragon before version 7.6.0. The software's APIs do not properly enforce limits on the number or size of incoming requests. A remote attacker with high privileges can exploit this lack of throttling or allocation limits to achieve arbitrary code execution. The attack requires a high level of complexity and existing administrative-level permissions, resulting in a CVSS score of 5.5. The issue is addressed in version 7.6.0.

Affected products

  • HCL Technologies Dragon before 7.6.0

Timeline

  • 2025-12-03: advisory
  • 2025-12-03: disclosed

References