A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
During installation, installed file permissions are set to allow anyone to modify those files.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0105705 | vendor advisory |