CVE-2024-42213 Details
Description
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.
A vulnerability in HCL BigFix Compliance exists due to temporary files being unintentionally left in the production environment. These files could be accessed by an attacker through indexing, predictable URLs, or misconfigured permissions, resulting in unauthorized information disclosure.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120961 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-531 | Inclusion of Sensitive Information in Test Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hcltech bigfix compliance | 2.0.12 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2025 | Initial Analysis | [email protected] |
| May 5, 2025 | New CVE Received | [email protected] |