HCL Technologies BigFix Insights是美国HCL Technologies公司的通过端点队列数据的提升视图、丰富的报告以及与现有商业智能工具的集成,加快风险识别和决策制定。 HCL Technologies BigFix Insights 存在安全漏洞,该漏洞源于在某些 Fixlet 内容中使用了不正确的凭证处理。攻击者利用该漏洞可以访问未明确授权的信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL Software | BigFix Insights for Vulnerability Remediation | <=2.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-37538 | 9.3 CRITICAL | HCL Digital Experience is susceptible to cross site scripting (XSS) |
| CVE-2023-37536 | 8.2 HIGH | HCL BigFix Platform is vulnerable to an integer overflow in xerces-c++ 3.2.3 |
| CVE-2022-44757 | 6.5 MEDIUM | HCL BigFix Insights for Vulnerability Remediation (IVR) is vulnerable to weak cryptography |
| CVE-2022-42451 | 4.6 MEDIUM | HCL BigFix Patch Management is vulnerable to insecurely stored credentials |
No comments yet