CVEs (33)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache FedoraprojectHcltech3Bigfix Platform FedoraXerces C++Jun 17, 2026 Oct 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. |
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.
|
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
|
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page. |
BigFix Web Reports authorized users may see SMTP credentials in clear text. |
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updati...Show more |
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updatin...Show more |
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by upd...Show more |
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses |
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks |
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it. |
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cooki...Show more |
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These creden...Show more |