CVE-2023-37529
HCL BigFix Server vulnerability analysis and mitigation

Overview

A cross-site scripting (XSS) vulnerability exists in the Web Reports component of HCL BigFix Platform (CVE-2023-37529). The vulnerability was discovered and disclosed on February 28, 2024, affecting multiple versions of the platform including versions 9.5 through 9.5.23, 10.0 through 10.0.10, and 11.0.0. This vulnerability could potentially allow an attacker to execute malicious JavaScript code into a webpage attempting to retrieve cookie stored information (HCL Advisory).

Technical details

The vulnerability is classified as a cross-site scripting (XSS) issue that specifically affects the Web Reports component. The CVSS Base Score is 3.0 LOW with a vector of CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N, indicating a network-attackable vulnerability with high attack complexity, requiring low privileges and user interaction (HCL Advisory).

Impact

If successfully exploited, the vulnerability could allow an attacker to execute malicious JavaScript code in a webpage that is attempting to retrieve cookie stored information. This could potentially lead to unauthorized access to sensitive cookie data (HCL Advisory).

Exploitability

The vulnerability requires low privileges and user interaction to exploit, with high attack complexity. The attack vector is network-based, meaning it can be exploited remotely. However, the CVSS scoring indicates that the actual exploitation difficulty is relatively high (HCL Advisory).

Mitigation and workarounds

HCL has released patches to address this vulnerability. Users of BigFix Platform 11.0.0 should upgrade to Patch 11.0.1, users of version 10.0.10 should upgrade to Patch 10.0.11, and users of version 9.5.23 should upgrade to Patch 9.5.24. These patches can be found and applied through the associated upgrade-patch fixlets in the Console. No other workarounds or mitigations have been provided (HCL Advisory).

Community reactions

The vulnerability was reported to HCLSoftware by security researcher Kajetan Rostojek, along with several other related XSS vulnerabilities in the same product (HCL Advisory).

Additional resources


SourceThis report was generated using AI

Related HCL BigFix Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21765HIGH7.8
  • HCL BigFix Server logoHCL BigFix Server
  • cpe:2.3:a:hcltech:bigfix_platform
NoNoApr 02, 2026
CVE-2024-42189MEDIUM5.6
  • HCL BigFix Server logoHCL BigFix Server
  • cpe:2.3:a:hcltech:bigfix_platform
NoYesApr 15, 2025
CVE-2024-42200MEDIUM4.8
  • HCL BigFix Server logoHCL BigFix Server
  • cpe:2.3:a:hcltech:bigfix_platform
NoYesApr 15, 2025
CVE-2026-21767LOW3.3
  • HCL BigFix Server logoHCL BigFix Server
  • cpe:2.3:a:hcltech:bigfix_platform
NoNoApr 02, 2026
CVE-2024-42193LOW2.1
  • HCL BigFix Server logoHCL BigFix Server
  • cpe:2.3:a:hcltech:bigfix_platform
NoYesApr 15, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management