CVE-2022-27544Insufficiently Protected Credentials in Bigfix Platform

Severity
6.5MEDIUMNVD
CNA5.0
EPSS
0.2%
top 59.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateJul 20

Description

BigFix Web Reports authorized users may see SMTP credentials in clear text.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDhcltech/bigfix_platform9.59.5.19+1
CVEListV5hcl_software/hcl_bigfix9.5, 10.0

🔴Vulnerability Details

2
GHSA
GHSA-fc76-hxx9-92hh: BigFix Web Reports authorized users may see SMTP credentials in clear text2022-07-20
CVEList
HCL BigFix Web Reports authorized users may see sensitive information in clear text2022-07-19
CVE-2022-27544 — Insufficiently Protected Credentials | cvebase