CVE-2025-15633
MEDIUM6.5CVSS v3
—CVSS v2
0.03%
EPSS (exploit probability)
CWE-863CWE
Description
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.