VYPR

Bigfix Platform

by HCLTech

CVEs (33)

  • CVE-2026-21765HigApr 2, 2026
    risk 0.57cvss 8.8epss 0.00

    HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.

  • CVE-2024-42193HigApr 15, 2025
    risk 0.53cvss 8.1epss 0.00

    HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead…

  • CVE-2023-37536HigOct 11, 2023
    risk 0.53cvss 8.2epss 0.01

    An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

  • CVE-2023-37520HigDec 21, 2023
    risk 0.50cvss 7.7epss 0.00

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.

  • CVE-2023-37519HigDec 21, 2023
    risk 0.50cvss 7.7epss 0.00

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server. 

  • CVE-2020-14254HigDec 16, 2020
    risk 0.49cvss 7.5epss 0.01

    TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.

  • CVE-2022-42453MedDec 19, 2022
    risk 0.45cvss 6.9epss 0.00

    There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.

  • CVE-2024-23583MedMay 17, 2024
    risk 0.44cvss 6.7epss 0.00

    An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.

  • CVE-2021-27767MedMay 6, 2022
    risk 0.44cvss 6.7epss 0.00

    The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying…

  • CVE-2021-27766MedMay 6, 2022
    risk 0.44cvss 6.7epss 0.00

    The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying…

  • CVE-2021-27765MedMay 6, 2022
    risk 0.44cvss 6.7epss 0.00

    The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying…

  • CVE-2024-42189MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

  • CVE-2023-37528MedFeb 3, 2024
    risk 0.42cvss 6.5epss 0.00

    A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.

  • CVE-2022-38659MedDec 19, 2022
    risk 0.39cvss 6.0epss 0.00

    In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.

  • CVE-2020-4095MedJul 16, 2020
    risk 0.39cvss 6.0epss 0.00

    "BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment.…

  • CVE-2024-23556MedMay 18, 2024
    risk 0.38cvss 5.9epss 0.00

    SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.

  • CVE-2024-23554MedMay 18, 2024
    risk 0.37cvss 5.7epss 0.00

    Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).

  • CVE-2024-42200MedApr 15, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.

  • CVE-2023-37527MedFeb 2, 2024
    risk 0.35cvss 5.4epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.

  • CVE-2020-14248MedDec 16, 2020
    risk 0.35cvss 5.3epss 0.01

    BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

Page 1 of 2