VYPR

BigFix Inventory

by HCL Software

CVEs (6)

  • CVE-2020-14254HigDec 16, 2020
    risk 0.49cvss 7.5epss 0.01

    TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.

  • CVE-2020-14248MedDec 16, 2020
    risk 0.35cvss 5.3epss 0.01

    BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

  • CVE-2024-23540MedApr 3, 2024
    risk 0.34cvss 5.3epss 0.01

    The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file.

  • CVE-2021-27758MedMay 6, 2022
    risk 0.28cvss 4.3epss 0.00

    There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.

  • CVE-2024-42194LowDec 17, 2024
    risk 0.20cvss 3.1epss 0.00

    An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.

  • CVE-2021-27759LowMay 6, 2022
    risk 0.15cvss 2.3epss 0.00

    This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.