HCL BigFix Patch Download Plug-ins Insecure Support for File URI Scheme Vulnerability
Vulnerability
A vulnerability exists in HCL BigFix Patch Download Plug-ins due to insecure handling of the file URI scheme. This flaw could enable a malicious operator to download files from arbitrary locations using the file:// URI scheme. The vulnerability affects several different versions and/or ranges of the BigFix Patch Download Plug-ins.
Impact
Exploitation of this vulnerability could lead to unauthorized file downloads from the local file system, potentially allowing for the retrieval of sensitive information or the introduction of malicious files into the application environment.
Remediation
Users can upgrade to HCL BigFix Patching Support, site version 1177 or later. Instructions for upgrading are available in the HCL BigFix Patch Management Download Plug-ins Security Bulletin.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
