HCL BigFix Remote Control
cpe:2.3:a:ibm:bigfix_remote_control:*:*:*:*:*:*:*
- <= 10.1.0.0442
A vulnerability exists in HCL BigFix Remote Control Server WebUI in versions through 10.1.0.0442. The issue arises from a misconfigured Content Security Policy (CSP) that fails to establish directives without fallbacks. This flaw enables attackers to circumvent intended security measures and load unauthorized resources.
Exploitation of this vulnerability allows for bypassing of security restrictions, potentially leading to the loading of unauthorized resources.
Users can upgrade to HCL BigFix Remote Control Remote Control 10.1 Fix Pack 5 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.