PT-2025-42441 · Hcl · Hcl Bigfix Mobile
Published
2025-10-16
·
Updated
2025-10-21
·
CVE-2025-0277
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
HCL BigFix Mobile versions 3.3 and earlier
Description
The software contains insecure directives within the Content Security Policy (CSP). An attacker could potentially mislead users into performing unintended actions due to improper restrictions on script and content sources.
Recommendations
Update to a newer version of HCL BigFix Mobile to address the issue.
Fix
Protection Mechanism Failure
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hcl Bigfix Mobile