A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.
SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.
An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.
The console may experience a service interruption when processing file names with invalid characters.