The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file.
References
Configurations
No configuration.
History
21 Nov 2024, 08:57
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0112015 - |
12 Jul 2024, 16:11
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-22 | |
Summary |
|
03 Apr 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-03 17:15
Updated : 2024-11-21 08:57
NVD link : CVE-2024-23540
Mitre link : CVE-2024-23540
CVE.ORG link : CVE-2024-23540
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')