HCL BigFix Remote Control is affected by an authorization bypass vulnerability

CVE Details

Basic Information

Title HCL BigFix Remote Control is affected by an authorization bypass vulnerability
Type cve
Published 2025-07-29T16:53:03.338Z
Modified 2025-07-29T16:53:03.338Z

Product Information

Vendor HCL Software
Product BigFix Remote Control
Version <=10.1.0.0248

CVSS Information

Base Score 8.2 (HIGH)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:L

Affected Products

  • HCL Software BigFix Remote Control <=10.1.0.0248

Additional Information

CWE List CWE-305
Source HCL

Description

Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information on certain web pages.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.