HCL BigFix WebUI is affected by a missing-permission-check vulnerability
CVE-2022-38655

5.8MEDIUM

Key Information:

Vendor
CVE Published:
21 December 2022

What is CVE-2022-38655?

BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.

Affected Version(s)

BigFix WebUI 20

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.