HCL BigFix Patch Download Plug-ins Arbitrary File Download Vulnerability
Vulnerability
An arbitrary file download vulnerability has been identified in HCL BigFix Patch Download Plug-ins, specifically in versions prior to 1177. This vulnerability allows a malicious operator to download files from any URL without proper validation or allowlist controls.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive files or data.
Remediation
Users can upgrade to HCL BigFix Patching Support, site version 1177 or later. Instructions for upgrading are available in the HCL BigFix Patch Management Download Plug-ins Security Bulletin.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
5.2remediation
7.7relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
