CVE-2023-37525
EUVD-2023-4141228.01.2026, 20:16
A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hcltech | bigfix_compliance | 2.0.9 |
𝑥
= Vulnerable software versions