CVE-2025-15634
EUVD-2025-20975409.05.2026, 06:16
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hcltech | bigfix_webui_api | 𝑥 < 33 |
| hcltech | bigfix_webui_application_administration | 𝑥 < 40 |
| hcltech | bigfix_webui_cmep | 𝑥 < 22 |
| hcltech | bigfix_webui_common | 𝑥 < 101 |
| hcltech | bigfix_webui_content_app | 𝑥 < 28 |
| hcltech | bigfix_webui_custom | 𝑥 < 50 |
| hcltech | bigfix_webui_data_sync | 𝑥 < 37 |
| hcltech | bigfix_webui_extensions | 𝑥 < 14 |
| hcltech | bigfix_webui_framework | 𝑥 < 35 |
| hcltech | bigfix_webui_insights | 𝑥 < 32 |
| hcltech | bigfix_webui_ivr | 𝑥 < 23 |
| hcltech | bigfix_webui_mdm | 𝑥 < 29 |
| hcltech | bigfix_webui_patch | 𝑥 < 54 |
| hcltech | bigfix_webui_patch_policies | 𝑥 < 51 |
| hcltech | bigfix_webui_permissions_and_preferences | 𝑥 < 27 |
| hcltech | bigfix_webui_profile_management | 𝑥 < 33 |
| hcltech | bigfix_webui_query | 𝑥 < 45 |
| hcltech | bigfix_webui_reports | 𝑥 < 24 |
| hcltech | bigfix_webui_scm | 𝑥 < 20 |
| hcltech | bigfix_webui_software_distribution | 𝑥 < 54 |
| hcltech | bigfix_webui_take_action | 𝑥 < 37 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration