CVE-2025-59849

I

mproper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*

History

06 Jan 2026, 19:54

Type Values Removed Values Added
First Time Hcltechsw hcl Launch
Hcltechsw
Hcltechsw hcl Devops Deploy
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127332 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127332 - Vendor Advisory
CPE cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*

18 Dec 2025, 15:07

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 21:16

Updated : 2026-01-06 19:54


NVD link : CVE-2025-59849

Mitre link : CVE-2025-59849

CVE.ORG link : CVE-2025-59849


JSON object : View

CWE
CWE-693

Protection Mechanism Failure

CWE-1021

Improper Restriction of Rendered UI Layers or Frames