VYPR

BigFix Web Reports

by HCL Software

CVEs (5)

  • CVE-2024-42193HigApr 15, 2025
    risk 0.53cvss 8.1epss 0.00

    HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead…

  • CVE-2024-42189MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

  • CVE-2024-42200MedApr 15, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.

  • CVE-2022-27544MedJul 19, 2022
    risk 0.33cvss 5.0epss 0.00

    BigFix Web Reports authorized users may see SMTP credentials in clear text.

  • CVE-2022-27545MedJul 19, 2022
    risk 0.30cvss 4.6epss 0.00

    BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.