HCL
HCL Bigfix Service Management: vulnerabilidades y CVE
HCL Bigfix Service Management tiene 18 vulnerabilidades publicadas, 18 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses18
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-67172 | Baja (3.7) | 0.21% | — | 1 oct 2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This… |
| CVE-2026-67171 | Media (5.3) | 0.24% | — | 1 oct 2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to… |
| CVE-2025-31980 | Media (4.3) | 0.16% | — | 1 oct 2026 | HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or… |
| CVE-2026-67106 | Media (5.3) | 0.24% | — | 1 oct 2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious… |
| CVE-2026-67105 | Alta (7.4) | 0.15% | — | 1 oct 2026 | HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling… |
| CVE-2026-67104 | Media (5.3) | 0.24% | — | 1 oct 2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the discovery of hidden… |
| CVE-2026-56599 | Baja (2.2) | 0.06% | — | 1 oct 2026 | HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and… |
| CVE-2026-56589 | Alta (7.2) | 0.20% | — | 1 oct 2026 | HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views… |
| CVE-2026-21806 | Baja (3.1) | 0.15% | — | 18 sept 2026 | HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could… |
| CVE-2026-56597 | Baja (3.1) | 0.25% | — | 18 sept 2026 | HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them… |
| CVE-2026-56595 | Baja (3.1) | 0.24% | — | 18 sept 2026 | HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the… |
| CVE-2026-56592 | Media (6.5) | 0.45% | — | 18 sept 2026 | HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force… |
| CVE-2026-56590 | Media (6.4) | 0.29% | — | 18 sept 2026 | HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads,… |
| CVE-2026-21848 | Media (5) | 0.16% | — | 18 sept 2026 | HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted… |
| CVE-2026-67103 | Alta (7.6) | 0.28% | — | 18 sept 2026 | HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session… |
| CVE-2026-67102 | Alta (8.1) | 0.35% | — | 18 sept 2026 | HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for… |
| CVE-2026-67101 | Crítica (9.3) | 0.34% | — | 18 sept 2026 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal… |
| CVE-2026-67100 | Crítica (9.8) | 0.47% | — | 18 sept 2026 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.