Vulnerabilities
Vulnerable Software
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.
CVSS Score
2.5
EPSS Score
0.0
Published
2024-10-14
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
CVSS Score
5.3
EPSS Score
0.001
Published
2020-12-16
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
CVSS Score
7.5
EPSS Score
0.002
Published
2020-12-16


Contact Us

Shodan ® - All rights reserved