CVE-2023-37525

Publication date

2026-01-28 19:58:49

Family

HCL

State

PUBLISHED

Description

A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files and configuration information, leading to unauthorized access to application internals.