CVE-2022-44758: HCL BigFix Insights for Vulnerability Remediation (IVR) is vulnerable to improper credential handling
Published Oct 11, 2023
·Updated
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.
Affected Software
1 affected component
hcltech Bigfix Insights For Vulnerability Remediation<2.0.3
Event History
Oct 11, 2023
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionSeverity
Data Sourced
07:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-44758?
CVE-2022-44758 is a vulnerability in BigFix Insights/IVR that allows an attacker to gain unauthorized access to information.
2
How does CVE-2022-44758 affect Hcltech Bigfix Insights For Vulnerability Remediation?
CVE-2022-44758 affects Hcltech Bigfix Insights For Vulnerability Remediation version up to exclusive 2.0.3.
3
What is the severity of CVE-2022-44758?
CVE-2022-44758 has a severity level of 6.5 (Medium).
4
How can an attacker exploit CVE-2022-44758?
An attacker can exploit CVE-2022-44758 by using improper credential handling within certain fixlet content in BigFix Insights/IVR.
5
Is there a fix available for CVE-2022-44758?
Please refer to the following link for information on fixing CVE-2022-44758: [https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108005]