← Back

CVE-2025-52621

nvd nist
Published: Aug 15, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning.  The BigFix SaaS's HTTP responses were observed to include the Origin header. Its presence alongside an unvalidated reflection of the Origin header value introduces a potential for cache poisoning.

Affected (1)

Products: Hcltech: Bigfix Saas
1 product
Bigfix Saas
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 8.1.14

Timeline

No history available yet.