Unrated severityNVD Advisory· Published Jan 28, 2026· Updated Jan 29, 2026
HCL BigFix Compliance is vulnerable to a sensitive information disclosure
CVE-2023-37525
Description
A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.
Affected products
1- Range: 2.0.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.