Hcltech

Bigfix Mobile

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 16.10.2025 08:27:54
  • Zuletzt bearbeitet 21.10.2025 18:15:34

HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

  • EPSS 0.05%
  • Veröffentlicht 16.10.2025 08:25:49
  • Zuletzt bearbeitet 21.10.2025 13:03:12

HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of script...

  • EPSS 0.04%
  • Veröffentlicht 16.10.2025 05:14:24
  • Zuletzt bearbeitet 21.10.2025 18:17:18

HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

  • EPSS 0.04%
  • Veröffentlicht 16.10.2025 04:56:49
  • Zuletzt bearbeitet 21.10.2025 18:21:10

HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

  • EPSS 0.5%
  • Veröffentlicht 27.07.2023 00:15:13
  • Zuletzt bearbeitet 21.11.2024 07:53:55

HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.

  • EPSS 0.11%
  • Veröffentlicht 27.07.2023 00:15:13
  • Zuletzt bearbeitet 21.11.2024 07:53:55

HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.

  • EPSS 0.22%
  • Veröffentlicht 20.01.2023 07:15:10
  • Zuletzt bearbeitet 02.04.2025 15:15:40

HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.

  • EPSS 0.21%
  • Veröffentlicht 27.05.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 05:58:33

The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.

  • EPSS 0.21%
  • Veröffentlicht 27.05.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 05:58:33

The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.

  • EPSS 0.11%
  • Veröffentlicht 25.05.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 05:58:33

User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.