Unrated severityNVD Advisory· Published Jan 28, 2026· Updated Jan 29, 2026
HCL BigFix Compliance is vulnerable to a sensitive information disclosure
CVE-2023-37525
Description
A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: 2.0.9
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.