MEDIUM🇵🇱 Wersja polska

CVE-2024-42213

CVSS 5.3v3.1pub. 2025-05-05upd. 2025-06-17

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • Hcltech Bigfix Compliance

    APP
    Hcltech
    2.0.12
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-27756HIGH7.5same product

"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are n...

CVE-2023-37525MEDIUM5.3same product

Wrażliwe ujawnienie informacji w HCL BigFix Compliance umożliwia zdalnemu atakującemu dostęp do plików w katal...

CVE-2024-42212MEDIUM5.4same product

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site R...

CVE-2024-30140MEDIUM5.4same product

HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated b...

CVE-2024-30141MEDIUM4.7same product

HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Det...