HCL BigFix Platform 10

CPE Details

HCL BigFix Platform 10
10
2022-05-13
12h29 +00:00
2022-07-30
01h52 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:hcltech:bigfix_platform:10:*:*:*:*:*:*:*

Informations

Vendor

hcltech

Product

bigfix_platform

Version

10

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-45705 2024-03-28 14h11 +00:00 An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.
7.2
High
CVE-2022-38659 2022-12-17 18h44 +00:00 In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
7.8
High
CVE-2021-27767 2022-05-06 18h10 +00:00 The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
7.8
High
CVE-2021-27766 2022-05-06 18h10 +00:00 The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
7.8
High
CVE-2021-27765 2022-05-06 18h10 +00:00 The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
7.8
High
CVE-2020-14248 2020-12-16 13h11 +00:00 BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
5.3
Medium
CVE-2020-14254 2020-12-16 13h07 +00:00 TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
7.5
High