Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech bigfix Remote Control |
|
| Vendors & Products |
Hcltech
Hcltech bigfix Remote Control |
Wed, 17 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages. | |
| Title | HCL BigFix Remote Control is vulnerable to an insecure CSP configuration | |
| Weaknesses | CWE-1021 CWE-693 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published: 2025-12-17T20:28:22.768Z
Updated: 2025-12-17T20:45:21.930Z
Reserved: 2025-09-22T14:59:58.051Z
Link: CVE-2025-59849
Updated: 2025-12-17T20:43:37.779Z
Status : Awaiting Analysis
Published: 2025-12-17T21:16:14.873
Modified: 2025-12-18T15:07:42.550
Link: CVE-2025-59849
No data.