HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.
References
Link | Resource |
---|---|
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120961 | Vendor Advisory |
Configurations
History
17 Jun 2025, 21:04
Type | Values Removed | Values Added |
---|---|---|
First Time |
Hcltech
Hcltech bigfix Compliance |
|
CPE | cpe:2.3:a:hcltech:bigfix_compliance:2.0.12:*:*:*:*:*:*:* | |
Summary |
|
|
References | () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120961 - Vendor Advisory |
05 May 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-05 19:15
Updated : 2025-06-17 21:04
NVD link : CVE-2024-42213
Mitre link : CVE-2024-42213
CVE.ORG link : CVE-2024-42213
JSON object : View
Products Affected
hcltech
- bigfix_compliance
CWE
CWE-531
Inclusion of Sensitive Information in Test Code