Home

Description

An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.

PUBLISHED Reserved 2026-04-14 | Published 2026-05-09 | Updated 2026-05-09 | Assigner HCL




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

Problem types

CWE-863 Incorrect Authorization

Product status

Default status
unaffected

all versions
affected

References

support.hcl-software.com/...rticle&sysparm_article=KB0130587

cve.org (CVE-2025-15633)

nvd.nist.gov (CVE-2025-15633)

Download JSON