Executive brief
HCL MyCloud, a cloud management platform, is affected by a security flaw where software license keys are inadvertently included in web server responses. An authorized user could potentially view these keys, leading to unauthorized software use or further security compromises. This issue primarily impacts the confidentiality of licensing information rather than direct system availability.
Technical details
HCL MyCloud version 10.8.2 is vulnerable to sensitive information disclosure (CWE-200) because the application includes license keys within HTTP responses. An authenticated attacker with network access can capture these responses to extract the keys. While the attack complexity is rated as high, the exposure allows for the potential misuse of licensing data. Users are advised to consult HCL security bulletin KB0132381 for remediation steps.
Affected products
- HCL Software MyCloud 10.8.2
Timeline
- 2026-07-21: advisory
- 2026-07-21: disclosed