HCL Technologies HCL BigFix Platform是印度HCL Technologies公司的一套端点安全管理平台。该平台支持自动发现、管理和修复端点安全问题。 HCL Technologies BigFix Platform 存在数据伪造问题漏洞,该漏洞源于应用程序允许用户执行某些敏感操作,而无需验证请求是否是有意发送的。攻击者利用该漏洞可以使受害者的浏览器向应用程序中的任意URL发出HTTP请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL Software | HCL BigFix Inventory | 9.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-27764 | 7.4 HIGH | HCL BigFix WebUI Cookie missing attributes |
| CVE-2021-27765 | 6.7 MEDIUM | HCL BigFix Platform Server API is affected by Privilege Escalation Vulnerability |
| CVE-2021-27766 | 6.7 MEDIUM | HCL BigFix Platform Client is affected by a Privilege Escalation Vulnerability |
| CVE-2021-27767 | 6.7 MEDIUM | HCL BigFix Platform Console is affected by a Privilege Escalation Vulnerability |
| CVE-2021-27761 | 4.8 MEDIUM | HCL BigFix Platform is affected by weak web transport security |
| CVE-2021-27762 | 4.7 MEDIUM | HCL BigFix Platform is affected by misconfigured security-related HTTP headers |
| CVE-2021-27760 | 4.6 MEDIUM | HCL Notes 11.0 - 11.0.1 FP4 Sametime Embedded chat clients are vulnerable to group chats l |
| CVE-2021-27751 | 4.4 MEDIUM | HCL Commerce is affected by an Insufficient Session Expiration vulnerability. |
| CVE-2021-27758 | 4.3 MEDIUM | HCL BigFix Platform 跨站请求伪造漏洞 |
No comments yet