CVE-2024-42194: HCL BigFix Inventory is affected by an access control vulnerability
An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42194?
CVE-2024-42194 has been classified as a high severity vulnerability due to the potential for unauthorized configuration changes.
How do I fix CVE-2024-42194?
To fix CVE-2024-42194, ensure that proper permissions are configured for REST API access and restrict read-only accounts from making configuration changes.
Who is affected by CVE-2024-42194?
CVE-2024-42194 affects organizations using HCL BigFix Inventory with improperly configured user permissions.
What type of attack does CVE-2024-42194 enable?
CVE-2024-42194 enables attackers with read-only access to possibly alter configuration parameters via crafted REST API calls.
What systems should be monitored for CVE-2024-42194?
All instances of HCL BigFix Inventory should be monitored for attempts to exploit CVE-2024-42194 through unauthorized API calls.