First published: Sat Dec 17 2022(Updated: )
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Platform | >=9.5<=9.5.20 | |
Hcltech Bigfix Platform | >=10<=10.0.7 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-38659.
The severity of CVE-2022-38659 is high (7.8).
Hcltech Bigfix Platform versions 9.5.20 and earlier, and versions 10.0.7 and earlier are affected by CVE-2022-38659.
In specific scenarios on Windows, the operator credentials may be encrypted in a manner that is not completely machine-dependent.
No, Microsoft Windows is not vulnerable to CVE-2022-38659.
Apply the latest updates provided by Hcltech for Bigfix Platform to fix CVE-2022-38659.
You can find more information about CVE-2022-38659 [here](https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102049).
The CWE ID of CVE-2022-38659 is 326.