VendorsHcltechbigfix_platformany version
Vulnerabilities

Hcltech HCL any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

33CVEs
CVE-2021-27762
HCL BigFix Platform is affected by misconfigured security-related HTTP headers
Published 2022-05-06 · Modified
9.8EPSS 0.007
CVE-2023-37536
HCL BigFix Platform is vulnerable to an integer overflow in xerces-c++ 3.2.3
Published 2023-10-11 · Modified
8.8EPSS 0.014
CVE-2024-23554
HCL BigFix Platform is susceptible to Cross-Site Request Forgery
Published 2024-05-17 · Analyzed
8.8EPSS 0.003
CVE-2026-21765
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys
Published 2026-04-01 · Analyzed
8.8EPSS 0.001
CVE-2024-42193
HCL BigFix Web Reports is susceptible to a Man-In-The-Middle (MITM) attack
Published 2025-04-15 · Analyzed
8.1EPSS 0.003
CVE-2021-27765
HCL BigFix Platform Server API is affected by Privilege Escalation Vulnerability
Published 2022-05-06 · Modified
7.8EPSS 0.003
CVE-2021-27766
HCL BigFix Platform Client is affected by a Privilege Escalation Vulnerability
Published 2022-05-06 · Modified
7.8EPSS 0.002
CVE-2021-27767
HCL BigFix Platform Console is affected by a Privilege Escalation Vulnerability
Published 2022-05-06 · Modified
7.8EPSS 0.002
CVE-2022-38659
HCL BigFix Platform is affected by insecure credential storage
Published 2022-12-17 · Modified
7.8EPSS 0.001
CVE-2023-37520
HCL BigFix Platform is affected by Unathenticated Stored Cross-Site Scripting (XSS)
Published 2023-12-21 · Modified
7.7EPSS 0.003
CVE-2023-37519
HCL BigFix Platform is affected by Unathenticated Stored Cross-Site Scripting (XSS)
Published 2023-12-21 · Modified
7.7EPSS 0.002
CVE-2020-14254
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
Published 2020-12-16 · Modified
7.5EPSS 0.006
CVE-2021-27761
HCL BigFix Platform is affected by weak web transport security
Published 2022-05-06 · Modified
7.5EPSS 0.004
CVE-2024-23556
HCL BigFix Platform is impacted by a failure to restrict SSL/TLS renegotiation
Published 2024-05-17 · Analyzed
7.5EPSS 0.004
CVE-2023-45705
HCL BigFix Platform is susceptible to Server Side Request Forgery (SSRF)
Published 2024-03-28 · Modified
7.2EPSS 0.004
CVE-2022-42453
HCL BigFix Platform is affected by insufficient warnings
Published 2022-12-17 · Modified
6.9EPSS 0.003
CVE-2024-23583
HCL BigFix Platform is susceptible to insufficiently protected credentials
Published 2024-05-17 · Analyzed
6.7EPSS 0.002
CVE-2022-27544
HCL BigFix Web Reports authorized users may see sensitive information in clear text
Published 2022-07-19 · Modified
6.5EPSS 0.004
CVE-2023-37528
A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform
Published 2024-02-03 · Modified
6.5EPSS 0.003
CVE-2024-42189
HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack
Published 2025-04-15 · Analyzed
6.5EPSS 0.003
CVE-2023-37527
A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform
Published 2024-02-02 · Modified
6.1EPSS 0.004
CVE-2020-4095
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."
Published 2020-07-16 · Modified
6.0EPSS 0.002
CVE-2023-37529
A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform
Published 2024-02-02 · Modified
5.4EPSS 0.003
CVE-2023-37530
A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform
Published 2024-02-02 · Modified
5.4EPSS 0.003
CVE-2022-27545
HCL BigFix Web Reports authorized users may perform HTML injection.
Published 2022-07-19 · Modified
5.4EPSS 0.003
CVE-2024-23553
A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform
Published 2024-02-02 · Modified
5.4EPSS 0.003
CVE-2024-42200
HCL BigFix Web Reports is potentially susceptible to a Stored Cross-Site Scripting (XSS) attack
Published 2025-04-15 · Analyzed
5.4EPSS 0.002
CVE-2020-14248
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Published 2020-12-16 · Modified
5.3EPSS 0.007
CVE-2024-30117
HCL BigFix Platform is affected by a DLL Hijack vulnerability
Published 2024-10-14 · Analyzed
5.3EPSS 0.002
CVE-2023-37531
A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform
Published 2024-02-02 · Modified
4.8EPSS 0.004
CVE-2023-45715
HCL BigFix Platform is susceptible to a Denial of Service attack
Published 2024-03-28 · Analyzed
4.3EPSS 0.004
CVE-2023-45706
HCL BigFix Platform is susceptible to Cross Site Scripting (XSS) and/or Man in the Middle (MITM) attack
Published 2024-03-28 · Analyzed
4.0EPSS 0.003
CVE-2026-21767
HCL BigFix Platform is affected by insufficient authentication
Published 2026-04-01 · Analyzed
4.0EPSS 0.001