Vulnerabilities > Hcltech > Bigfix Platform > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-11 CVE-2023-37536 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
network
low complexity
hcltech apache fedoraproject CWE-190
8.8
2022-12-19 CVE-2022-38659 Inadequate Encryption Strength vulnerability in Hcltech Bigfix Platform
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
local
low complexity
hcltech CWE-326
7.8
2022-05-06 CVE-2021-27761 Inadequate Encryption Strength vulnerability in Hcltech Bigfix Platform
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
network
low complexity
hcltech CWE-326
7.5
2022-05-06 CVE-2021-27765 Improper Privilege Management vulnerability in Hcltech Bigfix Platform
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation.
local
low complexity
hcltech CWE-269
7.8
2022-05-06 CVE-2021-27766 Improper Privilege Management vulnerability in Hcltech Bigfix Platform
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation.
local
low complexity
hcltech CWE-269
7.8
2022-05-06 CVE-2021-27767 Improper Privilege Management vulnerability in Hcltech Bigfix Platform
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation.
local
low complexity
hcltech CWE-269
7.8
2020-12-16 CVE-2020-14254 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Hcltech Bigfix Platform
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2.
network
low complexity
hcltech CWE-327
7.5