Overview : |
HCL BigFix Inventory does not enforce “secure” attribute for SSO related cookies when SSO is enabled. Web browsers might expose cookie via unsecured channel when end user is already logged in the application and enters manually http URL instead of https. The cookie might be used to get access to specific information. It is not sufficient to get access to the HCL BigFix Inventory application. |
Affected Product(s) : |
|
Vulnerability Details : |
||||||
Solution :
Note: BigFix Inventory v10 is continuation for v9 as well. Standard application update can be run on top of both v10 and v9. |