CVE-2024-42213: Hcltech Bigfix Compliance
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.
Affected products
- Hcltech Bigfix Compliance: version 2.0.12 only
Published 2025-05-05. Last modified 2026-06-17.