📦 Bigfix Platform

by Hcltech

🔍 What is Bigfix Platform?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-42193

HIGH CVSS 8.1 Apr 15, 2025

HCL BigFix Web Reports has improper SSL certificate validation, allowing man-in-the-middle attacks. Attackers could intercept and manipulate HTTPS communications, potentially exposing sensitive data o...

CVE-2023-37520

HIGH CVSS 7.7 Dec 21, 2023

An unauthenticated stored cross-site scripting (XSS) vulnerability in BigFix Server version 9.5.12.68 allows attackers to inject malicious scripts into the Gather Status Report, which is served by Big...

CVE-2023-37519

HIGH CVSS 7.7 Dec 21, 2023

CVE-2023-37519 is an unauthenticated stored cross-site scripting (XSS) vulnerability in the Download Status Report feature of BigFix Server. Attackers can inject malicious scripts that execute when us...

CVE-2024-42200

MEDIUM CVSS 5.4 Apr 15, 2025

HCL BigFix Web Reports has a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into web pages. When users view affected pages, the scripts execute in their br...

CVE-2024-23554

MEDIUM CVSS 5.7 May 18, 2024

This CVE describes a Cross-Site Request Forgery vulnerability affecting session tokens in HCL software. If exploited, attackers could trick authenticated users into performing unintended actions, pote...