GHSA-957m-p4pq-mxmf · Severity: medium — A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without...
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.
Conclusion & alert: CVE-2025-15634 is rated Low Risk (24.4/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.03%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-09 | — | 0.03% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
GHSA-957m-p4pq-mxmf · Severity: medium — A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| hcltech | bigfix_webui_api | < 33 | cpe:2.3:a:hcltech:bigfix_webui_api:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_application_administration | < 40 | cpe:2.3:a:hcltech:bigfix_webui_application_administration:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_cmep | < 22 | cpe:2.3:a:hcltech:bigfix_webui_cmep:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_common | < 101 | cpe:2.3:a:hcltech:bigfix_webui_common:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_content_app | < 28 | cpe:2.3:a:hcltech:bigfix_webui_content_app:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_custom | < 50 | cpe:2.3:a:hcltech:bigfix_webui_custom:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_data_sync | < 37 | cpe:2.3:a:hcltech:bigfix_webui_data_sync:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_extensions | < 14 | cpe:2.3:a:hcltech:bigfix_webui_extensions:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_framework | < 35 | cpe:2.3:a:hcltech:bigfix_webui_framework:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_insights | < 32 | cpe:2.3:a:hcltech:bigfix_webui_insights:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_ivr | < 23 | cpe:2.3:a:hcltech:bigfix_webui_ivr:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_mdm | < 29 | cpe:2.3:a:hcltech:bigfix_webui_mdm:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_patch | < 54 | cpe:2.3:a:hcltech:bigfix_webui_patch:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_patch_policies | < 51 | cpe:2.3:a:hcltech:bigfix_webui_patch_policies:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_permissions_and_preferences | < 27 | cpe:2.3:a:hcltech:bigfix_webui_permissions_and_preferences:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_profile_management | < 33 | cpe:2.3:a:hcltech:bigfix_webui_profile_management:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_query | < 45 | cpe:2.3:a:hcltech:bigfix_webui_query:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_reports | < 24 | cpe:2.3:a:hcltech:bigfix_webui_reports:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_scm | < 20 | cpe:2.3:a:hcltech:bigfix_webui_scm:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_software_distribution | < 54 | cpe:2.3:a:hcltech:bigfix_webui_software_distribution:*:*:*:*:*:*:*:* |
| hcltech | bigfix_webui_take_action | < 37 | cpe:2.3:a:hcltech:bigfix_webui_take_action:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130587 | Vendor Advisory |