Multiple vulnerabilities in OpenSSL affect HCL VersionVault / HCL DevOps Code ClearCase
Security Bulletin: Multiple vulnerabilities in OpenSSL affect HCL VersionVault / HCL DevOps Code ClearCase
Summary OpenSSL vulnerabilities were disclosed by the OpenSSL Project. OpenSSL is used by HCL VersionVault / HCL DevOps Code ClearCase. Vulnerability Details CVEID: CVE-2025-11187 Description: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification may lead to stack buffer overflow or NULL pointer dereference during processing of malformed inputs, potentially causing denial of service or code execution depending on platform mitigations. CVSS Base Score: 6.1 (Medium) CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H CVEID: CVE-2025-66199 Description: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit CVSS Base Score: 5.9 (Medium) CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVEID: CVE-2025-22795 Description: A type confusion vulnerability in OpenSSL's PKCS#12 parsing causes ASN1_TYPE validation absence, leading to denial of service when parsing malformed PKCS#12 data. (openssl-library.org) CVSS Base Score: 5.5 (Medium) CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVEID: CVE-2025-22796 Description: ASN1_TYPE type confusion in OpenSSL's PKCS#7 signature verification where malformed PKCS#7 data can lead to denial of service due to invalid pointer dereference. CVSS Base Score: 5.3 (Medium) CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Link to Security Bulletin Please see the security bulletin for vulnerability details and remediation: Multiple vulnerabilities in OpenSSL affect HCL VersionVault / HCL DevOps Code ClearCase
OpenSSL vulnerabilities were disclosed by the OpenSSL Project. OpenSSL is used by HCL VersionVault / HCL DevOps Code ClearCase.
Vulnerability Details
CVEID: CVE-2025-11187 Description: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification may lead to stack buffer overflow or NULL pointer dereference during processing of malformed inputs, potentially causing denial of service or code execution depending on platform mitigations.
CVSS Base Score: 6.1 (Medium) CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H
CVEID: CVE-2025-66199 Description: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit CVSS Base Score: 5.9 (Medium) CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEID: CVE-2025-22795 Description: A type confusion vulnerability in OpenSSL's PKCS#12 parsing causes ASN1_TYPE validation absence, leading to denial of service when parsing malformed PKCS#12 data. (openssl-library.org) CVSS Base Score: 5.5 (Medium) CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVEID: CVE-2025-22796 Description: ASN1_TYPE type confusion in OpenSSL's PKCS#7 signature verification where malformed PKCS#7 data can lead to denial of service due to invalid pointer dereference. CVSS Base Score: 5.3 (Medium) CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Link to Security Bulletin
Please see the security bulletin for vulnerability details and remediation: Multiple vulnerabilities in OpenSSL affect HCL VersionVault / HCL DevOps Code ClearCase
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
