BigFix WebUI
by HCL Software
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-27764 | Hig | 0.48 | 7.4 | 0.01 | May 6, 2022 | Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI) | ||
| CVE-2022-38655 | Med | 0.42 | 6.4 | 0.00 | Dec 21, 2022 | BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site. | ||
| CVE-2025-52647 | Med | 0.40 | 6.1 | 0.00 | Oct 10, 2025 | The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks. | ||
| CVE-2023-28021 | Med | 0.38 | 5.9 | 0.00 | Jul 18, 2023 | The BigFix WebUI uses weak cipher suites. | ||
| CVE-2023-28019 | Med | 0.36 | 5.5 | 0.00 | Jul 18, 2023 | Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query. | ||
| CVE-2020-4104 | Med | 0.35 | 5.4 | 0.01 | Jul 17, 2020 | HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in… | ||
| CVE-2022-27544 | Med | 0.33 | 5.0 | 0.00 | Jul 19, 2022 | BigFix Web Reports authorized users may see SMTP credentials in clear text. | ||
| CVE-2023-28020 | Med | 0.31 | 4.7 | 0.00 | Jul 18, 2023 | URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header. | ||
| CVE-2022-27545 | Med | 0.30 | 4.6 | 0.00 | Jul 19, 2022 | BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page. |
- risk 0.48cvss 7.4epss 0.01
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)
- risk 0.42cvss 6.4epss 0.00
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.
- risk 0.40cvss 6.1epss 0.00
The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks.
- risk 0.38cvss 5.9epss 0.00
The BigFix WebUI uses weak cipher suites.
- risk 0.36cvss 5.5epss 0.00
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.
- risk 0.35cvss 5.4epss 0.01
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in…
- risk 0.33cvss 5.0epss 0.00
BigFix Web Reports authorized users may see SMTP credentials in clear text.
- risk 0.31cvss 4.7epss 0.00
URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
- risk 0.30cvss 4.6epss 0.00
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.