Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2024-30142

Disclosure Date: November 07, 2024 (last updated November 07, 2024)
HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.
0
Attacker Value
Unknown

CVE-2024-30141

Disclosure Date: November 07, 2024 (last updated November 07, 2024)
HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about its environment, users, or associated data.
0
Attacker Value
Unknown

CVE-2024-30140

Disclosure Date: November 07, 2024 (last updated November 07, 2024)
HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.
0
Attacker Value
Unknown

CVE-2024-30126

Disclosure Date: July 18, 2024 (last updated July 19, 2024)
HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.
0
Attacker Value
Unknown

CVE-2024-30125

Disclosure Date: July 18, 2024 (last updated July 19, 2024)
HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.
0
Attacker Value
Unknown

CVE-2024-23551

Disclosure Date: May 07, 2024 (last updated May 08, 2024)
Database scanning using username and password stores the credentials in plaintext or encoded format within files at the endpoint. This has been identified as a significant security risk. This will lead to exposure of sensitive information for unauthorized access, potentially leading to severe consequences such as data breaches, unauthorized data manipulation, and compromised system integrity.
0
Attacker Value
Unknown

CVE-2021-27756

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."
Attacker Value
Unknown

CVE-2017-1200

Disclosure Date: February 05, 2019 (last updated November 27, 2024)
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host. IBM X-Force ID: 123675.
0
Attacker Value
Unknown

CVE-2017-1202

Disclosure Date: February 05, 2019 (last updated November 27, 2024)
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 123677.
0
Attacker Value
Unknown

CVE-2017-1177

Disclosure Date: February 05, 2019 (last updated November 27, 2024)
IBM BigFix Compliance 1.7 through 1.9.91 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 123429.
0