CVE-2025-15633

MEDIUM WAF: Low
CVSS 6.5 Published: 2026-05-09
CWE-863

An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.

WAF Coverage Analysis

Incorrect Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
hcltechbigfix_webui_apiup to 33
hcltechbigfix_webui_application_administrationup to 40
hcltechbigfix_webui_cmepup to 22
hcltechbigfix_webui_commonup to 101
hcltechbigfix_webui_content_appup to 28
hcltechbigfix_webui_customup to 50
hcltechbigfix_webui_data_syncup to 37
hcltechbigfix_webui_extensionsup to 14
hcltechbigfix_webui_frameworkup to 35
hcltechbigfix_webui_insightsup to 32

References

Back to CVE Database