Hcl Software Hcl Bigfix Inventory vulnerabilities
4 known vulnerabilities affecting hcl_software/hcl_bigfix_inventory.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2021-27759MEDIUMCVSS 6.5v9.xv10.x2022-05-06
CVE-2021-27759 [MEDIUM] CWE-352 CVE-2021-27759: This vulnerability arises because the application allows the user to perform some sensitive action w
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.
cvelistv5nvd
CVE-2021-27758MEDIUMCVSS 6.5v9.xv10.x2022-05-06
CVE-2021-27758 [MEDIUM] CWE-352 CVE-2021-27758: There is a security vulnerability in login form related to Cross-site Request Forgery which prevents
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.
cvelistv5nvd
CVE-2020-14254HIGHCVSS 7.5vv9.x, v10.x2020-12-16
CVE-2020-14254 [HIGH] CVE-2020-14254: TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
cvelistv5
CVE-2020-14248MEDIUMCVSS 5.3vv9, v10.0.x2020-12-16
CVE-2020-14248 [MEDIUM] CVE-2020-14248: BigFix Inventory up to v10
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
cvelistv5