Show filters
61 Total Results
Displaying 51-60 of 61
Sort by:
Attacker Value
Unknown
CVE-2023-28020
Disclosure Date: July 18, 2023 (last updated October 08, 2023)
URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
0
Attacker Value
Unknown
CVE-2023-28019
Disclosure Date: July 18, 2023 (last updated October 08, 2023)
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.
0
Attacker Value
Unknown
CVE-2023-23344
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
0
Attacker Value
Unknown
CVE-2022-38655
Disclosure Date: December 21, 2022 (last updated November 08, 2023)
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.
0
Attacker Value
Unknown
CVE-2021-27764
Disclosure Date: April 07, 2022 (last updated February 23, 2025)
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)
0
Attacker Value
Unknown
CVE-2020-4104
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855&sys_kb_id=971d99ed1b8ed01c086dcbfc0a4bcb6a.
0
Attacker Value
Unknown
CVE-2019-4012
Disclosure Date: April 15, 2019 (last updated November 27, 2024)
IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 155886.
0
Attacker Value
Unknown
CVE-2015-3912
Disclosure Date: May 21, 2015 (last updated October 05, 2023)
Huawei E355s Mobile WiFi with firmware before 22.158.45.02.625 and WEBUI before 13.100.04.01.625 allows remote attackers to obtain sensitive configuration information by sniffing the network or sending unspecified commands.
0
Attacker Value
Unknown
CVE-2014-8331
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3236 before E3276sTCPU-V200R002B470D13SP00C00 and E3276sWebUI-V100R007B100D03SP01C03 and E3276 before E3236sTCPU-V200R002B146D41SP00C00 and E3236sWebUI-V100R007B100D03SP01C03 allow remote attackers to hijack the authentication of administrators for requests that (1) change configuration settings or (2) use device functions.
0
Attacker Value
Unknown
CVE-2014-2946
Disclosure Date: June 02, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote attackers to hijack the authentication of administrators for requests that perform API operations and send SMS messages via a request element in an XML document.
0