5.3
CVE-2025-15634
- EPSS 0.02%
- Veröffentlicht 09.05.2026 05:05:33
- Zuletzt bearbeitet 14.05.2026 20:28:14
- Quelle psirt@hcl.com
- CVE-Watchlists
- Unerledigt
HCL BigFix WebUI is affected by a missing authorization vulnerability
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Bigfix Webui Api Version < 33
Hcltech ≫ Bigfix Webui Application Administration Version < 40
Hcltech ≫ Bigfix Webui Cmep Version < 22
Hcltech ≫ Bigfix Webui Common Version < 101
Hcltech ≫ Bigfix Webui Content App Version < 28
Hcltech ≫ Bigfix Webui Custom Version < 50
Hcltech ≫ Bigfix Webui Data Sync Version < 37
Hcltech ≫ Bigfix Webui Extensions Version < 14
Hcltech ≫ Bigfix Webui Framework Version < 35
Hcltech ≫ Bigfix Webui Insights Version < 32
Hcltech ≫ Bigfix Webui Ivr Version < 23
Hcltech ≫ Bigfix Webui Mdm Version < 29
Hcltech ≫ Bigfix Webui Patch Version < 54
Hcltech ≫ Bigfix Webui Patch Policies Version < 51
Hcltech ≫ Bigfix Webui Permissions And Preferences Version < 27
Hcltech ≫ Bigfix Webui Profile Management Version < 33
Hcltech ≫ Bigfix Webui Query Version < 45
Hcltech ≫ Bigfix Webui Reports Version < 24
Hcltech ≫ Bigfix Webui Scm Version < 20
Hcltech ≫ Bigfix Webui Software Distribution Version < 54
Hcltech ≫ Bigfix Webui Take Action Version < 37
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.07 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| psirt@hcl.com | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.