HCL BigFix Patch Download Plug-ins Arbitrary File Download Vulnerability

Vulnerability

An arbitrary file download vulnerability has been identified in HCL BigFix Patch Download Plug-ins, specifically in versions prior to 1177. This vulnerability allows a malicious operator to download files from any URL without proper validation or allowlist controls.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files or data.

Remediation

Users can upgrade to HCL BigFix Patching Support, site version 1177 or later. Instructions for upgrading are available in the HCL BigFix Patch Management Download Plug-ins Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.