CVE-2024-42187: Hcl Software Bigfix Patch Management Download Plug-Ins

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to download files from a local repository which is vulnerable to path traversal attacks.

Affected products

  • Hcl Software Bigfix Patch Management Download Plug-Ins: up to and including 1177

Published 2025-01-23. Last modified 2026-06-17.