All 6 CVE vulnerabilities found in BigFix Patch Management Download Plug-ins, with AI-generated Chinese analysis, references, and POCs.
Vendor: HCL Software
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-42187 | HCL BigFix Patch Download Plug-ins are affected by path traversal vulnerability CWE-22 | 5.3 | Medium | 2025-01-23 |
| CVE-2024-42186 | HCL BigFix Patch Download Plug-ins are affected by an insecure protocol support CWE-295 | 2.8 | Low | 2025-01-23 |
| CVE-2024-42185 | HCL BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks CWE-611 | 2.5 | Low | 2025-01-23 |
| CVE-2024-42184 | HCL BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme CWE-84 | 2.5 | Low | 2025-01-23 |
| CVE-2024-42183 | HCL BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability CWE-494 | 2.5 | Low | 2025-01-23 |
| CVE-2024-42182 | HCL BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability CWE-918 | 2.5 | Low | 2025-01-23 |
All 6 known CVE vulnerabilities affecting BigFix Patch Management Download Plug-ins with full Chinese analysis, references, and POCs where available.