HCL BigFix WebUI Host Header Poisoning Vulnerability

Vulnerability

A host header poisoning vulnerability has been identified in the HCL BigFix WebUI application. This issue arises because the application inadvertently exposes host information from the HTTP header, creating a potential vector for host header poisoning attacks. The vulnerability affects all versions of the BigFix WebUI application.

Impact

Exploitation of this vulnerability could lead to host header poisoning, allowing attackers to manipulate how the application interprets host headers. This could potentially be used to redirect users, interfere with application logic, or bypass security controls.

Remediation

Users are advised to upgrade to the latest version of HCL BigFix WebUI. Specific version recommendations can be found in the HCL BigFix WebUI Security Bulletin KB0124562.

Added: Oct 10, 2025, 11:22 PM
Updated: Oct 10, 2025, 11:22 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.3
exploitability
7.0
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.