VendorsHcltechbigfix_complianceall versions
Vulnerabilities

Hcltech HCL Technologies BigFix Compliance

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2021-27756
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."
Published 2022-03-04 · Modified
7.5EPSS 0.006
CVE-2024-30125
HCL BigFix Compliance is affected by an internal server error
Published 2024-07-18 · Analyzed
6.2EPSS 0.001
CVE-2024-30140
HCL BigFix Compliance is affected by unvalidated redirects and forwards
Published 2024-11-07 · Analyzed
5.4EPSS 0.002
CVE-2024-42212
HCL BigFix Compliance is affected by an improper or missing SameSite attribute
Published 2025-05-05 · Analyzed
5.4EPSS 0.002
CVE-2023-37525
HCL BigFix Compliance is vulnerable to a sensitive information disclosure
Published 2026-01-28 · Analyzed
5.3EPSS 0.003
CVE-2024-42213
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment
Published 2025-05-05 · Analyzed
5.3EPSS 0.003
CVE-2024-30141
HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information
Published 2024-11-07 · Analyzed
4.7EPSS 0.003
CVE-2024-30126
HCL BigFix Compliance is affected by a missing X-Frame-Options Header vulnerability
Published 2024-07-18 · Analyzed
4.7EPSS 0.002
CVE-2024-30142
HCL BigFix Compliance is affected by a missing secure flag on a cookie
Published 2024-11-07 · Analyzed
3.8EPSS 0.001