« Volver al listado

CVE-2021-27759

Estado: ModificadaMedia (6.5)—

This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-27759",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@hcl.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.3,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 0.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@hcl.com",
      "affectedData": [
        {
          "vendor": "HCL Software",
          "product": "HCL BigFix Inventory",
          "versions": [
            {
              "status": "affected",
              "version": "9.x"
            },
            {
              "status": "affected",
              "version": "10.x"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-05-06T18:15:08.643",
  "references": [
    {
      "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098006",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "psirt@hcl.com"
    },
    {
      "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098006",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@hcl.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-345"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application."
    },
    {
      "lang": "es",
      "value": "Esta vulnerabilidad surge porque la aplicación permite al usuario llevar a cabo alguna acción confidencial sin verificar que la petición fue enviada intencionalmente. Un atacante puede causar que el navegador de la víctima emita una petición HTTP a una URL arbitraria en la aplicación"
    }
  ],
  "lastModified": "2026-06-17T03:45:24.550",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hcltech:bigfix_inventory:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8977559C-10CF-4898-AF5F-A27B15C87579",
              "versionEndExcluding": "10.0.7.0",
              "versionStartIncluding": "9.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@hcl.com"
}