Vulnerabilities > Hcltech > Bigfix Platform > 10

DATE CVE VULNERABILITY TITLE RISK
2024-03-28 CVE-2023-45705 Server-Side Request Forgery (SSRF) vulnerability in Hcltech Bigfix Platform
An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.
network
low complexity
hcltech CWE-918
7.2
2022-12-19 CVE-2022-38659 Inadequate Encryption Strength vulnerability in Hcltech Bigfix Platform
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
local
low complexity
hcltech CWE-326
7.8
2022-05-06 CVE-2021-27765 Improper Privilege Management vulnerability in Hcltech Bigfix Platform
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation.
local
low complexity
hcltech CWE-269
7.8
2022-05-06 CVE-2021-27766 Improper Privilege Management vulnerability in Hcltech Bigfix Platform
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation.
local
low complexity
hcltech CWE-269
7.8
2022-05-06 CVE-2021-27767 Improper Privilege Management vulnerability in Hcltech Bigfix Platform
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation.
local
low complexity
hcltech CWE-269
7.8
2020-12-16 CVE-2020-14254 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Hcltech Bigfix Platform
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2.
network
low complexity
hcltech CWE-327
7.5
2020-12-16 CVE-2020-14248 Cleartext Transmission of Sensitive Information vulnerability in Hcltech Bigfix Platform
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
network
low complexity
hcltech CWE-319
5.3