VYPR

BigFix Server

by HCL Software

CVEs (3)

  • CVE-2023-37520HigDec 21, 2023
    risk 0.50cvss 7.7epss 0.00

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.

  • CVE-2023-37519HigDec 21, 2023
    risk 0.50cvss 7.7epss 0.00

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server. 

  • CVE-2022-38658HigDec 24, 2022
    risk 0.50cvss 7.7epss 0.00

    BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data…