Vulnerabilities > Hcltech > Bigfix Platform > 9.2

DATE CVE VULNERABILITY TITLE RISK
2023-10-11 CVE-2023-37536 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
network
low complexity
hcltech apache fedoraproject CWE-190
8.8
2020-12-16 CVE-2020-14254 Missing Encryption of Sensitive Data vulnerability in Hcltech Bigfix Platform
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2.
network
hcltech CWE-311
4.3
2020-12-16 CVE-2020-14248 Cleartext Transmission of Sensitive Information vulnerability in Hcltech Bigfix Platform
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
network
low complexity
hcltech CWE-319
5.0
2020-07-16 CVE-2020-4095 Insufficiently Protected Credentials vulnerability in Hcltech Bigfix Platform
"BigFix Platform is storing clear text credentials within the system's memory.
local
low complexity
hcltech CWE-522
2.1