Hcl Software Hcl Bigfix Platform vulnerabilities

5 known vulnerabilities affecting hcl_software/hcl_bigfix_platform.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4LOW1

Vulnerabilities

Page 1 of 1
CVE-2024-42200MEDIUMCVSS 4.8v10.0 - 10.0.12; 11.0.0 - 11.0.32025-04-15
CVE-2024-42200 [MEDIUM] CWE-79 CVE-2024-42200: HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a pote HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.
cvelistv5nvd
CVE-2024-42189MEDIUMCVSS 5.6v10.0 - 10.0.12; 11.0.0 - 11.0.32025-04-15
CVE-2024-42189 [MEDIUM] CWE-1287 CVE-2024-42189: HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially we HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.
cvelistv5nvd
CVE-2024-42193LOWCVSS 2.1v10.0 - 10.0.12; 11.0.0 - 11.0.32025-04-15
CVE-2024-42193 [LOW] CWE-295 CVE-2024-42193: HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of S HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.
cvelistv5nvd
CVE-2023-37520MEDIUMCVSS 6.1v9.5.x, 10.0.x, 11.0.02023-12-21
CVE-2023-37520 [MEDIUM] CWE-79 CVE-2023-37520: Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.
cvelistv5nvd
CVE-2023-37519MEDIUMCVSS 6.1v9.5.x, 10.0.x2023-12-21
CVE-2023-37519 [MEDIUM] CWE-79 CVE-2023-37519: Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Do Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server.
cvelistv5nvd