First published: Thu Dec 22 2022(Updated: )
BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data exposed.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Server Automation | <=3.2.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2022-38658.
The severity of CVE-2022-38658 is high with a CVSS score of 7.5.
BigFix deployments that have installed the Notification Service on Windows are affected by CVE-2022-38658.
Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data exposed.
No, Microsoft Windows is not vulnerable to CVE-2022-38658.
To fix CVE-2022-38658, it is recommended to follow the mitigation steps provided by Hcltech Support at (include reference link).