« Volver al listado

CVE-2025-52602

Estado: AplazadaMedia (4.2)—

HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application.  An HTTP GET endpoint request returns discoverable responses that may disclose: group names, active user names (or IDs).  An attacker can use that information to target individuals with phishing or other social-engineering attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-52602",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-52602",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-11-05T18:57:56.925811Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@hcl.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.2,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@hcl.com",
      "affectedData": [
        {
          "vendor": "HCL Software",
          "product": "BigFix Query",
          "versions": [
            {
              "status": "affected",
              "version": "site version < 43"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-11-05T15:15:39.337",
  "references": [
    {
      "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124950",
      "source": "psirt@hcl.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@hcl.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-359"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application.  An HTTP GET endpoint request returns discoverable responses that may disclose: group names, active user names (or IDs).   An attacker can use that information to target individuals with phishing or other social-engineering attacks."
    },
    {
      "lang": "es",
      "value": "HCL BigFix Query se ve afectado por una divulgación de información de información sensible en la aplicación WebUI Query. Una solicitud de punto final HTTP GET devuelve respuestas detectables que pueden revelar: nombres de grupo, nombres de usuario activos (o ID). Un atacante puede usar esa información para atacar a individuos con phishing u otros ataques de ingeniería social."
    }
  ],
  "lastModified": "2026-06-17T09:36:45.360",
  "sourceIdentifier": "psirt@hcl.com"
}