Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech bigfix Query |
|
| Vendors & Products |
Hcltech
Hcltech bigfix Query |
Wed, 05 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Nov 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application. An HTTP GET endpoint request returns discoverable responses that may disclose: group names, active user names (or IDs). An attacker can use that information to target individuals with phishing or other social-engineering attacks. | |
| Title | HCL BigFix Query is affected by a sensitive information disclosure vulnerability in the WebUI Query application | |
| Weaknesses | CWE-359 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2025-11-12T17:41:31.409Z
Reserved: 2025-06-18T14:00:38.417Z
Link: CVE-2025-52602
Updated: 2025-11-05T18:58:01.611Z
Status : Deferred
Published: 2025-11-05T15:15:39.337
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-52602
No data.
OpenCVE Enrichment
Updated: 2025-11-06T10:07:01Z