Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 21 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech bigfix Webui |
|
| Vendors & Products |
Hcltech
Hcltech bigfix Webui |
Tue, 14 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks. | |
| Title | HCL BigFix WebUI is affected by a host header poisoning vulnerability | |
| Weaknesses | CWE-644 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2025-10-14T15:00:24.739Z
Reserved: 2025-06-18T14:00:44.549Z
Link: CVE-2025-52647
Updated: 2025-10-14T15:00:21.297Z
Status : Deferred
Published: 2025-10-10T23:15:36.243
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-52647
No data.
OpenCVE Enrichment
Updated: 2025-10-21T13:14:07Z