Hcltech Bigfix Platform vulnerabilities
31 known vulnerabilities affecting hcltech/bigfix_platform.
Total CVEs
31
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM19LOW1
Vulnerabilities
Page 2 of 2
CVE-2022-42453MEDIUMCVSS 6.5≥ 9.5.0, < 9.5.21≥ 10.0.0, < 10.0.82022-12-19
CVE-2022-42453 [MEDIUM] CWE-287 CVE-2022-42453: There are insufficient warnings when a Fixlet is imported by a user. The warning message currently a
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.
nvd
CVE-2022-27544MEDIUMCVSS 6.5≥ 9.5, ≤ 9.5.19≥ 10.0, ≤ 10.0.62022-07-19
CVE-2022-27544 [MEDIUM] CWE-522 CVE-2022-27544: BigFix Web Reports authorized users may see SMTP credentials in clear text.
BigFix Web Reports authorized users may see SMTP credentials in clear text.
nvd
CVE-2022-27545MEDIUMCVSS 5.4≥ 9.5, ≤ 9.5.19≥ 10.0, ≤ 10.0.62022-07-19
CVE-2022-27545 [MEDIUM] CWE-79 CVE-2022-27545: BigFix Web Reports authorized users may perform HTML injection for the email administrative configur
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
nvd
CVE-2021-27762CRITICALCVSS 9.8≥ 9.5, < 9.5.19≥ 10.0, < 10.0.62022-05-06
CVE-2021-27762 [CRITICAL] CVE-2021-27762: Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-co
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses
nvd
CVE-2021-27767HIGHCVSS 7.8≥ 9.5, ≤ 9.5.18≥ 10, ≤ 10.0.52022-05-06
CVE-2021-27767 [HIGH] CWE-269 CVE-2021-27767: The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
nvd
CVE-2021-27765HIGHCVSS 7.8≥ 9.5, ≤ 9.5.18≥ 10, ≤ 10.0.52022-05-06
CVE-2021-27765 [HIGH] CWE-269 CVE-2021-27765: The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526,
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
nvd
CVE-2021-27761HIGHCVSS 7.5≥ 9.5, < 9.5.19≥ 10.0, < 10.0.62022-05-06
CVE-2021-27761 [HIGH] CWE-326 CVE-2021-27761: Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
nvd
CVE-2021-27766HIGHCVSS 7.8≥ 9.5, ≤ 9.5.18≥ 10, ≤ 10.0.52022-05-06
CVE-2021-27766 [HIGH] CWE-269 CVE-2021-27766: The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a v
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
nvd
CVE-2020-14254HIGHCVSS 7.5≤ 10.0.22020-12-16
CVE-2020-14254 [HIGH] CWE-327 CVE-2020-14254: TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
nvd
CVE-2020-14248MEDIUMCVSS 5.3≥ 9.0.0, ≤ 10.0.22020-12-16
CVE-2020-14248 [MEDIUM] CWE-319 CVE-2020-14248: BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https sessi
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
nvd
CVE-2020-4095MEDIUMCVSS 6.0≥ 9.2, ≤ 9.2.19≥ 9.5, ≤ 9.5.152020-07-16
CVE-2020-4095 [MEDIUM] CWE-312 CVE-2020-4095: "BigFix Platform is storing clear text credentials within the system's memory. An attacker who is ab
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments
nvd
← Previous2 / 2