First published: Tue Jul 19 2022(Updated: )
BigFix Web Reports authorized users may see SMTP credentials in clear text.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Platform | >=9.5<=9.5.19 | |
Hcltech Bigfix Platform | >=10.0<=10.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-27544.
The title of this vulnerability is 'BigFix Web Reports authorized users may see SMTP credentials in clear text.'
The severity rating of CVE-2022-27544 is medium with a value of 6.5.
BigFix Platform versions 9.5.0 to 9.5.19 and versions 10.0.0 to 10.0.6 are affected by CVE-2022-27544.
To prevent seeing SMTP credentials in clear text in BigFix Web Reports, authorized users should update to the latest version of BigFix Platform.
You can find more information about this vulnerability at the link provided: https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098998
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-522.