HCL BigFix Query is affected by a sensitive information...
Moderate severity
Unreviewed
Published
Nov 5, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Nov 5, 2025
Published to the GitHub Advisory Database
Nov 5, 2025
HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application. An HTTP GET endpoint request returns discoverable responses that may disclose: group names, active user names (or IDs). An attacker can use that information to target individuals with phishing or other social-engineering attacks.
References