HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.
| Software | From | Fixed in |
|---|---|---|
| hcltech / bigfix_platform | 10.0.0 | 10.0.13 |
| hcltech / bigfix_platform | 11.0.0 | 11.0.4 |