CVE-2025-15634

A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hcltech:bigfix_webui_api:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_application_administration:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_cmep:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_common:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_content_app:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_custom:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_data_sync:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_extensions:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_insights:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_ivr:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_mdm:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_patch:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_patch_policies:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_permissions_and_preferences:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_profile_management:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_query:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_reports:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_scm:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_software_distribution:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_webui_take_action:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-09 06:16

Updated : 2026-07-25 11:10


NVD link : CVE-2025-15634

Mitre link : CVE-2025-15634

CVE.ORG link : CVE-2025-15634


JSON object : View

Products Affected

hcltech

  • bigfix_webui_mdm
  • bigfix_webui_extensions
  • bigfix_webui_profile_management
  • bigfix_webui_software_distribution
  • bigfix_webui_framework
  • bigfix_webui_api
  • bigfix_webui_insights
  • bigfix_webui_patch
  • bigfix_webui_scm
  • bigfix_webui_permissions_and_preferences
  • bigfix_webui_reports
  • bigfix_webui_application_administration
  • bigfix_webui_cmep
  • bigfix_webui_ivr
  • bigfix_webui_query
  • bigfix_webui_data_sync
  • bigfix_webui_take_action
  • bigfix_webui_custom
  • bigfix_webui_patch_policies
  • bigfix_webui_common
  • bigfix_webui_content_app
CWE
CWE-862

Missing Authorization