First published: Tue Dec 20 2022(Updated: )
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Webui | =20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38655 is a vulnerability in BigFix WebUI that allows non-master operators to modify fixlet relevance or deploy fixlets from the BES Support external site.
The severity of CVE-2022-38655 is medium with a severity value of 5.8.
CVE-2022-38655 affects BigFix WebUI by allowing non-master operators to make unauthorized changes to fixlet relevance and deploy fixlets from the BES Support external site.
To fix CVE-2022-38655, it is recommended to update BigFix WebUI to version 20 or later.
You can find more information about CVE-2022-38655 on the HCL Support website: https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102140