"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NHcltech Bigfix Compliance
APPHcltech2.0 – 2.0.6 (bez)
Powiązane podatności
Wrażliwe ujawnienie informacji w HCL BigFix Compliance umożliwia zdalnemu atakującemu dostęp do plików w katal...
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An atta...
HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site R...
HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated b...
HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Det...