Hcltech
Hcltech Bigfix Insights FOR Vulnerability Remediation: vulnerabilidades y CVE
Hcltech Bigfix Insights FOR Vulnerability Remediation tiene 5 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-31964 | Media (4.9) | 0.35% | — | 7 ene 2026 | Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external… |
| CVE-2025-31963 | Baja (3.3) | 0.09% | — | 7 ene 2026 | Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated… |
| CVE-2025-31962 | Media (4.3) | 0.18% | — | 7 ene 2026 | Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive… |
| CVE-2022-44758 | Media (5.3) | 0.34% | — | 11 oct 2023 | BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized. |
| CVE-2022-44757 | Alta (8.2) | 0.33% | — | 11 oct 2023 | BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc. |