CVE-2025-55254

Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow to execute malicious code in certain web pages.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*

History

06 Jan 2026, 19:56

Type Values Removed Values Added
CWE CWE-613
CPE cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127332 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127332 - Vendor Advisory
First Time Hcltechsw hcl Devops Deploy
Hcltechsw
Hcltechsw hcl Launch

17 Dec 2025, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 21:16

Updated : 2026-01-06 19:56


NVD link : CVE-2025-55254

Mitre link : CVE-2025-55254

CVE.ORG link : CVE-2025-55254


JSON object : View

Products Affected

hcltechsw

  • hcl_devops_deploy
  • hcl_launch
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

CWE-613

Insufficient Session Expiration