Executive brief
HCL MyCloud, a cloud management platform, is affected by a security flaw that reveals specific server version information to unauthorized users. While this does not directly allow an attacker to take over the system, it provides them with a roadmap of known weaknesses associated with that specific version. This information can be used to plan more sophisticated attacks against the organization's infrastructure.
Technical details
HCL MyCloud version 10.8.2 is vulnerable to information exposure (CWE-200) via server version disclosure. An attacker with high privileges can remotely access version strings that identify the underlying software components. This metadata leak reduces the effort required for reconnaissance and allows an attacker to map the environment against known CVEs for those specific versions. The vulnerability is rated low severity because it requires high privileges and does not directly result in data modification or service disruption.
Affected products
- HCL Software MyCloud 10.8.2
Timeline
- 2026-07-21: advisory: HCL Software published the security bulletin KB0132381.
- 2026-07-21: disclosed