VYPR
Unrated severityNVD Advisory· Published Jan 28, 2026· Updated Jan 29, 2026

HCL BigFix Compliance is vulnerable to a sensitive information disclosure

CVE-2023-37525

Description

A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.