Bigfix Platform
by HCLTech
CVEs (33)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27544 | Med | 0.33 | 5.0 | 0.00 | Jul 19, 2022 | BigFix Web Reports authorized users may see SMTP credentials in clear text. | ||
| CVE-2021-27762 | Med | 0.31 | 4.7 | 0.01 | May 6, 2022 | Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses | ||
| CVE-2021-27761 | Med | 0.31 | 4.8 | 0.00 | May 6, 2022 | Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks | ||
| CVE-2022-27545 | Med | 0.30 | 4.6 | 0.00 | Jul 19, 2022 | BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page. | ||
| CVE-2026-21767 | Med | 0.26 | 4.0 | 0.00 | Apr 2, 2026 | HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive areas of the application without proper authentication. | ||
| CVE-2023-45715 | Low | 0.23 | 3.5 | 0.00 | Mar 28, 2024 | The console may experience a service interruption when processing file names with invalid characters. | ||
| CVE-2023-45705 | Low | 0.23 | 3.5 | 0.00 | Mar 28, 2024 | An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options. | ||
| CVE-2023-37531 | Low | 0.21 | 3.3 | 0.00 | Feb 29, 2024 | A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access. | ||
| CVE-2023-37530 | Low | 0.20 | 3.0 | 0.00 | Feb 29, 2024 | A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. | ||
| CVE-2023-37529 | Low | 0.20 | 3.0 | 0.00 | Feb 29, 2024 | A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerability as identified in… | ||
| CVE-2024-23553 | Low | 0.20 | 3.0 | 0.00 | Feb 2, 2024 | A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute. | ||
| CVE-2024-30117 | Low | 0.16 | 2.5 | 0.00 | Oct 14, 2024 | A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances. | ||
| CVE-2023-45706 | Low | 0.13 | 2.0 | 0.00 | Mar 28, 2024 | An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration. |
- risk 0.33cvss 5.0epss 0.00
BigFix Web Reports authorized users may see SMTP credentials in clear text.
- risk 0.31cvss 4.7epss 0.01
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses
- risk 0.31cvss 4.8epss 0.00
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
- risk 0.30cvss 4.6epss 0.00
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
- risk 0.26cvss 4.0epss 0.00
HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive areas of the application without proper authentication.
- risk 0.23cvss 3.5epss 0.00
The console may experience a service interruption when processing file names with invalid characters.
- risk 0.23cvss 3.5epss 0.00
An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.
- risk 0.21cvss 3.3epss 0.00
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.
- risk 0.20cvss 3.0epss 0.00
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information.
- risk 0.20cvss 3.0epss 0.00
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerability as identified in…
- risk 0.20cvss 3.0epss 0.00
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
- risk 0.16cvss 2.5epss 0.00
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.
- risk 0.13cvss 2.0epss 0.00
An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.
Page 2 of 2