HCL BigFix Web Reports service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.
The product does not validate, or incorrectly validates, a certificate.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Bigfix_platform | Hcltech | 10.0.0 (including) | 10.0.13 (excluding) |
| Bigfix_platform | Hcltech | 11.0.0 (including) | 11.0.4 (excluding) |