VendorsHcltechbigfix_webuiany version
Vulnerabilities

Hcltech HCL any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-28019
An SQL injection affects BigFix WebUI API
Published 2023-07-18 · Modified
8.8EPSS 0.004
CVE-2023-28021
BigFix WebUI is vulnerable to use of a risky cryptographic algorithm
Published 2023-07-18 · Modified
7.5EPSS 0.003
CVE-2021-27764
HCL BigFix WebUI Cookie missing attributes
Published 2022-05-06 · Modified
7.4EPSS 0.006
CVE-2023-28023
HCL BigFix WebUI Software Distribution is affected by a cross site server request forgery vulnerability
Published 2023-07-18 · Modified
6.5EPSS 0.002
CVE-2023-28020
URL redirection affects BigFix WebUI
Published 2023-07-18 · Modified
6.1EPSS 0.004
CVE-2020-4104
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855&sys_kb_id=971d99ed1b8ed01c086dcbfc0a4bcb6a.
Published 2020-07-17 · Modified
5.4EPSS 0.005