CVE-2025-59849Medium· 4.7▾ SunlitImproper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
hcl_devops_deploy >= 8.0.0.0, < 8.0.1.11hcl_devops_deploy >= 8.1.0, < 8.1.2.4hcl_launch >= 7.3.0.0, < 7.3.2.16Upgrade past the affected range:
hcl_devops_deploy 8.1.2.4hcl_launch 7.3.2.16Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62327Medium· 4.9In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries.
CVE-2026-56460Medium· 6.5HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
CVE-2026-56457Medium· 4.3HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs
CVE-2025-1018Medium· 5.3The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user
CVE-2025-1019Medium· 4.3The z-order of the browser windows could be manipulated to hide the fullscreen notification
CVE-2025-48597High· 7.8In multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack