CVE-2025-62338 PUBLISHED

The HCL BigFix Cloud Lifecycle Management is affected by Lack of Input Validation.

Assigner: HCL
Reserved: 10.10.2025 Published: 04.06.2026 Updated: 04.06.2026

The HCL BigFix Cloud Lifecycle Management is affected by Lack Of Input Validation. It may leads to an information exposure vulnerability. This low-level flaw allows unauthorized access.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 3.3

Product Status

Vendor HCL
Product BigFix Cloud Lifecycle Management
Versions Default: unaffected
  • Version 10.9.1 and 10.9.2 is affected

References

Problem Types

  • CWE 200 Exposure of Sensitive Information to an Unauthorized Actor