← Back

CVE-2025-15633

nvd nist
Published: May 9, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: psirt@hcl.com (Secondary)

Description

An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.

Affected (21)

21 products
Bigfix Webui Api
Bigfix Webui Cmep
Bigfix Webui Common
Bigfix Webui Content App
Bigfix Webui Custom
Bigfix Webui Data Sync
Bigfix Webui Extensions
Bigfix Webui Framework
Bigfix Webui Insights
Bigfix Webui Ivr
Bigfix Webui Mdm
Bigfix Webui Patch
Bigfix Webui Patch Policies
Bigfix Webui Profile Management
Bigfix Webui Query
Bigfix Webui Reports
Bigfix Webui Scm
Bigfix Webui Take Action
Configuration A
21 vulnerable

Timeline

No history available yet.