Skip to main content

Vendor/product archive

hcltech / bigfix_platform CVEs

Beta · best-effort

33 CVEs tagged to hcltech / bigfix_platform0 Critical, 5 High, 19 Medium, 9 Low, 0 Unrated.

CVE-2026-21767

Published Apr 2, 2026

HCL BigFix Platform is affected by insufficient authentication.  The application might allow users to access sensitive areas of the application without proper authentication.

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21765

Published Apr 2, 2026

HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-42193

Published Apr 15, 2025

HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-m…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42200

Published Apr 15, 2025

HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42189

Published Apr 15, 2025

HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30117

Published Oct 14, 2024

A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-23556

Published May 18, 2024

SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23554

Published May 18, 2024

Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45706

Published Mar 28, 2024

An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-45705

Published Mar 28, 2024

An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37531

Published Feb 29, 2024

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a form fiel…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37530

Published Feb 29, 2024

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage t…

CVSS 3.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37529

Published Feb 29, 2024

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage t…

CVSS 3.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37528

Published Feb 3, 2024

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23553

Published Feb 2, 2024

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.

CVSS 3.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37527

Published Feb 2, 2024

A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37520

Published Dec 21, 2023

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37519

Published Dec 21, 2023

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42453

Published Dec 19, 2022

There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warning…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27545

Published Jul 19, 2022

BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2