Show filters
72 Total Results
Displaying 11-20 of 72
Sort by:
Attacker Value
Unknown
CVE-2023-37528
Disclosure Date: February 03, 2024 (last updated February 13, 2024)
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during execution of the Save Report.
0
Attacker Value
Unknown
CVE-2024-23553
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
0
Attacker Value
Unknown
CVE-2023-37527
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code in the application session or in database, via remote injection, while rendering content in a web page.
0
Attacker Value
Unknown
CVE-2023-37520
Disclosure Date: December 21, 2023 (last updated December 30, 2023)
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.
0
Attacker Value
Unknown
CVE-2023-37519
Disclosure Date: December 21, 2023 (last updated December 30, 2023)
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server.
0
Attacker Value
Unknown
CVE-2023-37536
Disclosure Date: October 11, 2023 (last updated November 16, 2023)
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
0
Attacker Value
Unknown
CVE-2022-42453
Disclosure Date: December 19, 2022 (last updated November 08, 2023)
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.
0
Attacker Value
Unknown
CVE-2022-38659
Disclosure Date: December 19, 2022 (last updated November 08, 2023)
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
0
Attacker Value
Unknown
CVE-2022-27545
Disclosure Date: July 18, 2022 (last updated October 07, 2023)
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
0
Attacker Value
Unknown
CVE-2022-27544
Disclosure Date: July 18, 2022 (last updated October 07, 2023)
BigFix Web Reports authorized users may see SMTP credentials in clear text.
0