CVE-2025-59849: HCL BigFix Remote Control is vulnerable to an insecure CSP configuration
Published Dec 17, 2025
·Updated
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
Affected Software
4 affected components
HCL BigFix Remote Control Lite Web Portal<=10.1.0.0326
Hcltechsw Hcl Devops Deploy>=8.0.0.0<8.0.1.11
Hcltechsw Hcl Devops Deploy>=8.1.0<8.1.2.4
Hcltechsw Hcl Launch>=7.3.0.0<7.3.2.16
Event History
Dec 17, 2025
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59849?
CVE-2025-59849 has been classified with a high severity due to the potential for executing malicious code.
2
How do I fix CVE-2025-59849?
To remediate CVE-2025-59849, upgrade the HCL BigFix Remote Control Lite Web Portal to a version later than 10.1.0.0326.
3
Which versions of HCL BigFix Remote Control Lite are affected by CVE-2025-59849?
Versions 10.1.0.0326 and lower of HCL BigFix Remote Control Lite are affected by CVE-2025-59849.
4
What type of vulnerability is CVE-2025-59849?
CVE-2025-59849 is an improper management of Content Security Policy vulnerability.
5
What could be the impact of CVE-2025-59849?
The impact of CVE-2025-59849 could allow attackers to execute malicious code in web pages, compromising users' security.