CVE-2022-27544: HCL BigFix Web Reports authorized users may see sensitive information in clear text
BigFix Web Reports authorized users may see SMTP credentials in clear text.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-27544.
What is the title of this vulnerability?
The title of this vulnerability is 'BigFix Web Reports authorized users may see SMTP credentials in clear text.'
What is the severity rating of CVE-2022-27544?
The severity rating of CVE-2022-27544 is medium with a value of 6.5.
Which software versions are affected by CVE-2022-27544?
BigFix Platform versions 9.5.0 to 9.5.19 and versions 10.0.0 to 10.0.6 are affected by CVE-2022-27544.
How can authorized users prevent seeing SMTP credentials in clear text in BigFix Web Reports?
To prevent seeing SMTP credentials in clear text in BigFix Web Reports, authorized users should update to the latest version of BigFix Platform.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the link provided: https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098998
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-522.