CVE Vulnerabilities

CVE-2025-59849

Protection Mechanism Failure

Published: Dec 17, 2025 | Modified: Jan 06, 2026
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

NameVendorStart VersionEnd Version
Hcl_devops_deployHcltechsw8.0.0.0 (including)8.0.1.11 (excluding)
Hcl_devops_deployHcltechsw8.1.0 (including)8.1.2.4 (excluding)
Hcl_launchHcltechsw7.3.0.0 (including)7.3.2.16 (excluding)

References