PT-2026-6873 · Hcl · Hcl Velocity

CVE-2025-31990

·

Publicado

2026-02-07

·

Atualizado

2026-02-07

CVSS v3.1

6.8

Média

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HCL Velocity versions prior to 5.1.7
Description Rate limiting is not enforced for certain API calls, which makes the software vulnerable to Denial of Service (DoS) attacks. An attacker could send a large number of requests to overwhelm the system’s resources, causing it to become unresponsive to legitimate users.
Recommendations Update to version 5.1.7 or later.

Correção

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-31990

Produtos afetados

Hcl Velocity