HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-28062 HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 17 Jun 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech bigfix Compliance
CPEs cpe:2.3:a:hcltech:bigfix_compliance:*:*:*:*:*:*:*:*
Vendors & Products Hcltech
Hcltech bigfix Compliance

Wed, 30 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2024-10-30T16:24:33.273Z

Reserved: 2024-03-22T23:57:23.589Z

Link: CVE-2024-30126

cve-icon Vulnrichment

Updated: 2024-08-02T01:25:02.931Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-18T20:15:03.967

Modified: 2025-06-17T21:02:33.930

Link: CVE-2024-30126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.