An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 09 May 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers. | |
| Title | HCL BigFix WebUI is affected by an improper authorization vulnerability | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-05-09T04:58:55.241Z
Reserved: 2026-04-14T05:56:25.354Z
Link: CVE-2025-15633
No data.
Status : Received
Published: 2026-05-09T06:16:07.413
Modified: 2026-05-09T06:16:07.413
Link: CVE-2025-15633
No data.
OpenCVE Enrichment
No data.
Weaknesses