Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Filtered by product Bigfix Platform
Total 23 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-14254 1 Hcltech 1 Bigfix Platform 2024-11-21 4.3 MEDIUM 7.5 HIGH
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
CVE-2020-14248 1 Hcltech 1 Bigfix Platform 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
CVE-2024-30117 1 Hcltech 1 Bigfix Platform 2024-10-17 N/A 2.5 LOW
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.