CVE-2025-15634
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.
Published:May 9, 2026
Last Modified:May 14, 2026
EPS:May 9, 2026
EPSS Score:0.00031
CVSS Score:4.3
Affected Products
Vendor
Product
Action
Vendor
Hcltech
Product
Bigfix Webui
Hcltech
Bigfix Webui
Vendor
Hcltech
Product
Bigfix Webui Api
Hcltech
Bigfix Webui Api
Vendor
Hcltech
Product
Bigfix Webui Application Administration
Hcltech
Bigfix Webui Application Administration
Vendor
Hcltech
Product
Bigfix Webui Cmep
Hcltech
Bigfix Webui Cmep
Vendor
Hcltech
Product
Bigfix Webui Common
Hcltech
Bigfix Webui Common
Vendor
Hcltech
Product
Bigfix Webui Content App
Hcltech
Bigfix Webui Content App
Vendor
Hcltech
Product
Bigfix Webui Custom
Hcltech
Bigfix Webui Custom
Vendor
Hcltech
Product
Bigfix Webui Data Sync
Hcltech
Bigfix Webui Data Sync
Vendor
Hcltech
Product
Bigfix Webui Extensions
Hcltech
Bigfix Webui Extensions
Vendor
Hcltech
Product
Bigfix Webui Framework
Hcltech
Bigfix Webui Framework
Vendor
Hcltech
Product
Bigfix Webui Insights
Hcltech
Bigfix Webui Insights
Vendor
Hcltech
Product
Bigfix Webui Ivr
Hcltech
Bigfix Webui Ivr
Vendor
Hcltech
Product
Bigfix Webui Mdm
Hcltech
Bigfix Webui Mdm
Vendor
Hcltech
Product
Bigfix Webui Patch
Hcltech
Bigfix Webui Patch
Vendor
Hcltech
Product
Bigfix Webui Patch Policies
Hcltech
Bigfix Webui Patch Policies
Vendor
Hcltech
Product
Bigfix Webui Permissions And Preferences
Hcltech
Bigfix Webui Permissions And Preferences
Vendor
Hcltech
Product
Bigfix Webui Profile Management
Hcltech
Bigfix Webui Profile Management
Vendor
Hcltech
Product
Bigfix Webui Query
Hcltech
Bigfix Webui Query
Vendor
Hcltech
Product
Bigfix Webui Reports
Hcltech
Bigfix Webui Reports
Vendor
Hcltech
Product
Bigfix Webui Scm
Hcltech
Bigfix Webui Scm
Vendor
Hcltech
Product
Bigfix Webui Software Distribution
Hcltech
Bigfix Webui Software Distribution
Vendor
Hcltech
Product
Bigfix Webui Take Action
Hcltech
Bigfix Webui Take Action
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
