Skip to main content

Vendor/product archive

hcltech / bigfix_compliance CVEs

Beta · best-effort

9 CVEs tagged to hcltech / bigfix_compliance0 Critical, 1 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2023-37525

Published Jan 28, 2026

A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configurat…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42213

Published May 5, 2025

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via pr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42212

Published May 5, 2025

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a u…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30142

Published Nov 7, 2024

HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized acc…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30141

Published Nov 7, 2024

HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose inf…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30140

Published Nov 7, 2024

HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provid…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30126

Published Jul 18, 2024

HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or i…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30125

Published Jul 18, 2024

HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27756

Published Mar 4, 2022

"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1