PT-2026-39321 · Hclsoftware · Bigfix Webui

Published

2026-05-09

·

Updated

2026-05-09

·

CVE-2025-15634

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-15634

Affected Products

Bigfix Webui