Path Traversal Vulnerability in BigFix Patch Download Plug-ins by HCL Software
CVE-2024-42187 
5.3MEDIUM
What is CVE-2024-42187?
The BigFix Patch Download Plug-ins are susceptible to a path traversal vulnerability that allows unauthorized access to files in the local repository. This could enable nefarious actors to craft specially designed requests, potentially exposing sensitive data and compromising system integrity. Organizations using these plug-ins should implement immediate measures to mitigate this risk and ensure the security of their environment.
Affected Version(s)
BigFix Patch Management Download Plug-ins 1177 and below
