Page 2 of 8 results (0.003 seconds)

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site. A los operadores no maestros de BigFix WebUI les faltan controles que les impiden modificar la relevancia de los fixlets o implementar fixlets desde el sitio externo de soporte de BES. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102140 •

CVSS: 7.4EPSS: 0%CPEs: 1EXPL: 0

Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI) Cookie sin el flag HTTPONLY establecido. La cookie de NUMBER fue establecida sin los flags Secure o HTTPOnly. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0097778 • CWE-311: Missing Encryption of Sensitive Data CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute CWE-732: Incorrect Permission Assignment for Critical Resource •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855&sys_kb_id=971d99ed1b8ed01c086dcbfc0a4bcb6a. HCL BigFix WebUI es vulnerable a un ataque de tipo cross-site scripting (XSS) almacenado dentro del módulo Apps->Software. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •