CVE-2024-42213
MEDIUMDescription
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.
Is your site exposed to CVE-2024-42213?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| hcltech | bigfix_compliance |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-42213? +
How severe is CVE-2024-42213? +
What products are affected by CVE-2024-42213? +
How do I check if I'm vulnerable to CVE-2024-42213? +
Related Vulnerabilities
In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST …
HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious …
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may …
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a …
HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their …
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit …