Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Filtered by product Bigfix Platform
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-14248 1 Hcltech 1 Bigfix Platform 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
CVE-2024-30117 1 Hcltech 1 Bigfix Platform 2024-10-17 N/A 5.3 MEDIUM
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.