
Cloud Vulnerability DB
A community-led vulnerabilities database
BigFix Web Reports vulnerability (CVE-2022-27544) allows authorized users to view SMTP credentials in clear text. The vulnerability was discovered and assigned on March 21, 2022, affecting HCL Software's BigFix Web Reports system (CVE Mitre).
The vulnerability is classified under CWE-522, which relates to insufficiently protected credentials (NVD Status). The issue specifically involves the exposure of SMTP credentials in plain text format to authorized users of the BigFix Web Reports system.
The vulnerability exposes SMTP credentials to authorized users of the system, potentially compromising email server access and security (HCL Advisory).
HCL Software has acknowledged the vulnerability and provided information through their support portal (HCL Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."