
CVE-2023-37525 A sensitive information disclosure in HCL BigFix Compliance allows a remote attacker to access files under the WEB-INF directory, which may contain Java class files a… https://www.cve.org/CVERecord?id=CVE-2023-37525
Post summary
The text announces a new vulnerability (CVE-2023-37525) in HCL BigFix Compliance that allows remote disclosure of files in the WEB‑INF directory. No PoC, exploit, or patch is mentioned.
