CVE-2024-42194: Hcl Software Bigfix Inventory

Low severity, CVSS 3.1. EPSS: 0.3% chance of exploitation in the next 30 days.

An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.

Affected products

Published 2024-12-17. Last modified 2026-06-17.