An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.
Metrics
Affected Vendors & Products
References
History
Sat, 09 May 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers. | |
| Title | HCL BigFix WebUI is affected by an improper authorization vulnerability | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-05-09T04:58:55.241Z
Reserved: 2026-04-14T05:56:25.354Z
Link: CVE-2025-15633
No data.
Status : Received
Published: 2026-05-09T06:16:07.413
Modified: 2026-05-09T06:16:07.413
Link: CVE-2025-15633
No data.
OpenCVE Enrichment
Updated: 2026-05-09T07:00:11Z