CVE-2023-37525: Hcltech Bigfix Compliance
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.
Affected products
- Hcltech Bigfix Compliance: version 2.0.9 only
Published 2026-01-28. Last modified 2026-06-17.