{"id":"CVE-2025-59849","title":"Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.","summary":"Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.","severity":"medium","cvss":4.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-693","CWE-1021"],"vendor":"hcltechsw","product":"hcl_devops_deploy","affected":["hcl_devops_deploy >= 8.0.0.0, < 8.0.1.11","hcl_devops_deploy >= 8.1.0, < 8.1.2.4","hcl_launch >= 7.3.0.0, < 7.3.2.16"],"patched":["hcl_devops_deploy 8.1.2.4","hcl_launch 7.3.2.16"],"published":"2025-12-17","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-59849","references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127332","label":"psirt@hcl.com"}],"tags":["nvd"],"epss":0.00192,"epssPercentile":0.07946,"ingestedAt":"2026-09-30T23:29:32.498Z","slug":"CVE-2025-59849","body":"## Overview\n\nImproper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.\n\n## Affected\n\n- `hcl_devops_deploy >= 8.0.0.0, < 8.0.1.11`\n- `hcl_devops_deploy >= 8.1.0, < 8.1.2.4`\n- `hcl_launch >= 7.3.0.0, < 7.3.2.16`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `hcl_devops_deploy 8.1.2.4`\n- `hcl_launch 7.3.2.16`","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":25.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}