SQL Injection Vulnerability in HCL BigFix SaaS Authentication Service
CVE-2025-52618

4.3MEDIUM

Key Information:

Vendor
CVE Published:
15 August 2025

What is CVE-2025-52618?

The HCL BigFix SaaS Authentication Service is susceptible to a SQL injection vulnerability that enables unauthorized parties to manipulate SQL statements. This security flaw could lead to unauthorized access to sensitive data and potential compromise of the system, emphasizing the need for immediate mitigation strategies and updates.

Affected Version(s)

BigFix SaaS Remediate < 8.1.14

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52618 : SQL Injection Vulnerability in HCL BigFix SaaS Authentication Service