CVE-2023-37525: Hcltech Bigfix Compliance

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.

Affected products

  • Hcltech Bigfix Compliance: version 2.0.9 only

Published 2026-01-28. Last modified 2026-06-17.