Description
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CWE-419 Unprotected Primary Channel
Product status
4.2
References
support.hcl-software.com/...rticle&sysparm_article=KB0127753