CVE 5.3 MEDIUM

HCL BigFix WebUI is affected by an improper authorization vulnerability_CVE-2025-15633

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

Description

An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.

Basic Information

ID CVE-2025-15633
Source HCL
Published May 9, 2026 at 04:58

Affected Product

Vendor HCLSoftware
Product BigFix WebUI
Version all versions
Affected Versions HCLSoftware BigFix WebUI all versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.