CVE 5.3 MEDIUM

HCL BigFix WebUI is affected by a missing authorization vulnerability_CVE-2025-15634

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.

Basic Information

ID CVE-2025-15634
Source HCL
Published May 9, 2026 at 05:05

Affected Product

Vendor HCLSoftware
Product BigFix WebUI
Version all versions
Affected Versions HCLSoftware BigFix WebUI all versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.