A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 09 May 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | |
| Title | HCL BigFix WebUI is affected by a missing authorization vulnerability | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-05-09T05:05:33.534Z
Reserved: 2026-04-14T05:56:28.569Z
Link: CVE-2025-15634
No data.
Status : Received
Published: 2026-05-09T06:16:09.130
Modified: 2026-05-09T06:16:09.130
Link: CVE-2025-15634
No data.
OpenCVE Enrichment
Updated: 2026-05-09T06:30:25Z
Weaknesses