PT-2026-32380 · Hcl · Devops Velocity
Published
2026-04-13
·
Updated
2026-04-13
·
CVE-2025-31991
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
HCL DevOps Velocity versions prior to 5.1.7
Description
Rate limiting for user login attempts is not properly enforced, making the system susceptible to brute-force attacks that exceed the unsuccessful login attempt limit.
Recommendations
Update to version 5.1.7.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Devops Velocity