CVE-2025-55254

I

mproper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow to execute malicious code in certain web pages.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*

History

06 Jan 2026, 19:56

Type Values Removed Values Added
First Time Hcltechsw hcl Launch
Hcltechsw
Hcltechsw hcl Devops Deploy
CPE cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
CWE CWE-613
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127332 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127332 - Vendor Advisory

18 Dec 2025, 15:07

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 21:16

Updated : 2026-01-06 19:56


NVD link : CVE-2025-55254

Mitre link : CVE-2025-55254

CVE.ORG link : CVE-2025-55254


JSON object : View

CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

CWE-613

Insufficient Session Expiration