CVE 4.2 MEDIUM

HCL BigFix Query is affected by a sensitive information disclosure vulnerability in the WebUI Query application_CVE-2025-52602

4.2 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Description

HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application.  An HTTP GET endpoint request returns discoverable responses that may disclose: group names, active user names (or IDs).  An attacker can use that information to target individuals with phishing or other social-engineering attacks.

Basic Information

ID CVE-2025-52602
Source HCL
Published Nov 5, 2025 at 14:46
Modified Nov 5, 2025 at 18:58

Affected Product

Vendor HCL Software
Product BigFix Query
Version < 4.11.0
Affected Versions HCL Software BigFix Query < 4.11.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.