VYPR

BigFix Platform

by HCL Software

CVEs (32)

  • CVE-2021-27762MedMay 6, 2022
    risk 0.31cvss 4.7epss 0.01

    Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses

  • CVE-2021-27761MedMay 6, 2022
    risk 0.31cvss 4.8epss 0.00

    Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks

  • CVE-2026-21767MedApr 2, 2026
    risk 0.26cvss 4.0epss 0.00

    HCL BigFix Platform is affected by insufficient authentication.  The application might allow users to access sensitive areas of the application without proper authentication.

  • CVE-2023-45715LowMar 28, 2024
    risk 0.23cvss 3.5epss 0.00

    The console may experience a service interruption when processing file names with invalid characters.

  • CVE-2023-45705LowMar 28, 2024
    risk 0.23cvss 3.5epss 0.00

    An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.

  • CVE-2023-37531LowFeb 29, 2024
    risk 0.21cvss 3.3epss 0.00

    A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form field of a webpage by a user with privileged access.

  • CVE-2023-37530LowFeb 29, 2024
    risk 0.20cvss 3.0epss 0.00

    A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information.

  • CVE-2023-37529LowFeb 29, 2024
    risk 0.20cvss 3.0epss 0.00

    A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerability as identified in…

  • CVE-2024-23553LowFeb 2, 2024
    risk 0.20cvss 3.0epss 0.00

    A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.

  • CVE-2024-30117LowOct 14, 2024
    risk 0.16cvss 2.5epss 0.00

    A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.

  • CVE-2023-45706LowMar 28, 2024
    risk 0.13cvss 2.0epss 0.00

    An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.

  • CVE-2026-21840LowJul 14, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service.

Page 2 of 2