CVE-2025-15633
medium
CVSS v3
6.5
CVSS v2
—
VIR risk
6.5
Description
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@hcl.com — https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130587
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| hcltech | bigfix_webui_api | {"endExcluding":"33"} | 33 |
| hcltech | bigfix_webui_application_administration | {"endExcluding":"40"} | 40 |
| hcltech | bigfix_webui_cmep | {"endExcluding":"22"} | 22 |
| hcltech | bigfix_webui_common | {"endExcluding":"101"} | 101 |
| hcltech | bigfix_webui_content_app | {"endExcluding":"28"} | 28 |
| hcltech | bigfix_webui_custom | {"endExcluding":"50"} | 50 |
| hcltech | bigfix_webui_data_sync | {"endExcluding":"37"} | 37 |
| hcltech | bigfix_webui_extensions | {"endExcluding":"14"} | 14 |
| hcltech | bigfix_webui_framework | {"endExcluding":"35"} | 35 |
| hcltech | bigfix_webui_insights | {"endExcluding":"32"} | 32 |
| hcltech | bigfix_webui_ivr | {"endExcluding":"23"} | 23 |
| hcltech | bigfix_webui_mdm | {"endExcluding":"29"} | 29 |
| hcltech | bigfix_webui_patch | {"endExcluding":"54"} | 54 |
| hcltech | bigfix_webui_patch_policies | {"endExcluding":"51"} | 51 |
| hcltech | bigfix_webui_permissions_and_preferences | {"endExcluding":"27"} | 27 |
| hcltech | bigfix_webui_profile_management | {"endExcluding":"33"} | 33 |
| hcltech | bigfix_webui_query | {"endExcluding":"45"} | 45 |
| hcltech | bigfix_webui_reports | {"endExcluding":"24"} | 24 |
| hcltech | bigfix_webui_scm | {"endExcluding":"20"} | 20 |
| hcltech | bigfix_webui_software_distribution | {"endExcluding":"54"} | 54 |
| hcltech | bigfix_webui_take_action | {"endExcluding":"37"} | 37 |
References
CWEs
CWE-863
Verify integrity in audit chain (admin only). AS-IS.