HCL BigFix Platform
cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*
- >= 11.0.0, <= 11.0.5
A vulnerability exists in HCL BigFix Platform versions 11.0.0 through 11.0.5, related to insecure file permissions on private cryptographic keys. On Windows host machines, these keys may be exposed to overly permissive file system permissions, potentially allowing unauthorized access or modification.
The vulnerability could lead to unauthorized access or modification of private cryptographic keys, which may compromise the integrity and confidentiality of cryptographic operations and data protection within the application.
Users can upgrade to BigFix Platform version 11.0.6. Instructions for applying this patch are available in the BigFix Console.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.