CVE-2025-52621

Publication date

2025-08-15 22:45:55

Family

HCL

State

PUBLISHED

Description

HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning.  The BigFix SaaSs HTTP responses were observed to include the Origin header. Its presence alongside an unvalidated reflection of the Origin header value introduces a potential for cache poisoning.