HCL BigFix WebUI is affected by a missing-permission-check vulnerability
CVE-2022-38655
5.8MEDIUM
What is CVE-2022-38655?
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.
Affected Version(s)
BigFix WebUI 20
