Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
History

Wed, 17 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 17 Dec 2025 20:45:00 +0000

Type Values Removed Values Added
Description Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
Title HCL BigFix Remote Control is vulnerable to an insecure CSP configuration
Weaknesses CWE-1021
CWE-693
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2025-12-17T20:45:21.930Z

Reserved: 2025-09-22T14:59:58.051Z

Link: CVE-2025-59849

cve-icon Vulnrichment

Updated: 2025-12-17T20:43:37.779Z

cve-icon NVD

Status : Received

Published: 2025-12-17T21:16:14.873

Modified: 2025-12-17T21:16:14.873

Link: CVE-2025-59849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.