Vulnerabilities
Vulnerable Software
HCL BigFix Platform is affected by insufficient authentication.  The application might allow users to access sensitive areas of the application without proper authentication.
CVSS Score
4.0
EPSS Score
0.0
Published
2026-04-02
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.
CVSS Score
8.8
EPSS Score
0.0
Published
2026-04-02
HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.
CVSS Score
2.1
EPSS Score
0.001
Published
2025-04-15
HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.
CVSS Score
4.8
EPSS Score
0.001
Published
2025-04-15
HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.
CVSS Score
5.6
EPSS Score
0.002
Published
2025-04-15


Contact Us

Shodan ® - All rights reserved