VYPR
Unrated severityNVD Advisory· Published Jan 28, 2026· Updated Jan 29, 2026

HCL BigFix Compliance is vulnerable to a sensitive information disclosure

CVE-2023-37525

Description

A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.