Cache Poisoning Vulnerability in HCL BigFix SaaS Authentication Service
CVE-2025-52621

5.3MEDIUM

Key Information:

Vendor
CVE Published:
15 August 2025

What is CVE-2025-52621?

The HCL BigFix SaaS Authentication Service has a vulnerability that allows for cache poisoning attacks due to the inclusion of the Origin header in its HTTP responses. This can potentially lead to the exploitation of an unvalidated reflection of the header value, thereby compromising the integrity of cached content and enabling attackers to serve malicious responses.

Affected Version(s)

BigFix SaaS Remediate < 8.1.14

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52621 : Cache Poisoning Vulnerability in HCL BigFix SaaS Authentication Service