Vulnerabilities > Hcltech > Bigfix Platform > 9.5.7

DATE CVE VULNERABILITY TITLE RISK
2022-05-06 CVE-2021-27765 Improper Privilege Management vulnerability in Hcltech Bigfix Platform
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation.
local
low complexity
hcltech CWE-269
4.6
2022-05-06 CVE-2021-27766 Improper Privilege Management vulnerability in Hcltech Bigfix Platform
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation.
local
low complexity
hcltech CWE-269
4.6
2022-05-06 CVE-2021-27767 Improper Privilege Management vulnerability in Hcltech Bigfix Platform
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation.
local
low complexity
hcltech CWE-269
4.6
2020-12-16 CVE-2020-14254 Missing Encryption of Sensitive Data vulnerability in Hcltech Bigfix Platform
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2.
network
hcltech CWE-311
4.3
2020-12-16 CVE-2020-14248 Cleartext Transmission of Sensitive Information vulnerability in Hcltech Bigfix Platform
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
network
low complexity
hcltech CWE-319
5.0
2020-07-16 CVE-2020-4095 Insufficiently Protected Credentials vulnerability in Hcltech Bigfix Platform
"BigFix Platform is storing clear text credentials within the system's memory.
local
low complexity
hcltech CWE-522
2.1