CVE-2023-37525: HCL BigFix Compliance is vulnerable to a sensitive information disclosure
Published Jan 28, 2026
·Updated
A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.
Affected Software
2 affected components
HCL BigFix Compliance
hcltech Bigfix Compliance=2.0.9
Event History
Jan 28, 2026
CVE Published
via MITRE·07:58 PM
Data Sourced
via MITRE·07:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37525?
CVE-2023-37525 has been classified as a high severity vulnerability.
2
How does CVE-2023-37525 affect HCL BigFix Compliance?
CVE-2023-37525 allows unauthorized remote access to sensitive files within the WEB-INF directory.
3
Who is affected by CVE-2023-37525?
Organizations using HCL BigFix Compliance are potentially affected by CVE-2023-37525.
4
How can I mitigate the risks associated with CVE-2023-37525?
To mitigate CVE-2023-37525, restrict access to the WEB-INF directory and update to the latest version of HCL BigFix Compliance.
5
What information could be exposed by CVE-2023-37525?
CVE-2023-37525 could expose sensitive Java class files and configuration information, allowing for unauthorized access.