CVE-2025-59868 Details
Description
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application.
A sensitive data exposure vulnerability has been identified in HCL Traveler for Microsoft Outlook (HTMO) versions prior to 3.0.15. This vulnerability could allow an attacker to exploit application information, potentially leading to additional attacks and causing unknown behavior within the application.
Users are advised to download and install the latest version of HCL Traveler for Microsoft Outlook (HTMO), which includes the necessary fix. Additional download and installation information can be found in the HCL Traveler for Microsoft Outlook 3.0.x Release Notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131419 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hcltech traveler for microsoft outlook | < 3.0.15 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | Initial Analysis | [email protected] |
| Jun 29, 2026 | CVE Modified | CISA-ADP |
| Jun 27, 2026 | New CVE Received | [email protected] |