CVE-2025-31980
- EPSS 0.16%
- Veröffentlicht 01.10.2026 16:17:54
- Zuletzt bearbeitet 08.10.2026 13:17:14
HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing...
CVE-2026-67172
- EPSS 0.21%
- Veröffentlicht 01.10.2026 16:16:05
- Zuletzt bearbeitet 06.10.2026 16:46:45
HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to ...
CVE-2026-67171
- EPSS 0.24%
- Veröffentlicht 01.10.2026 16:15:22
- Zuletzt bearbeitet 06.10.2026 16:46:37
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks.
CVE-2026-67106
- EPSS 0.24%
- Veröffentlicht 01.10.2026 15:01:08
- Zuletzt bearbeitet 05.10.2026 17:25:11
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks.
CVE-2026-56599
- EPSS 0.06%
- Veröffentlicht 01.10.2026 15:00:00
- Zuletzt bearbeitet 05.10.2026 17:25:31
HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabling Cross-Site...
CVE-2026-67104
- EPSS 0.24%
- Veröffentlicht 01.10.2026 14:59:31
- Zuletzt bearbeitet 05.10.2026 17:24:38
HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the discovery of hidden administrative API endpoints for fur...
CVE-2026-67105
- EPSS 0.16%
- Veröffentlicht 01.10.2026 14:57:45
- Zuletzt bearbeitet 05.10.2026 17:25:08
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data...
CVE-2026-56589
- EPSS 0.2%
- Veröffentlicht 01.10.2026 14:55:42
- Zuletzt bearbeitet 05.10.2026 17:25:18
HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling se...
CVE-2026-67103
- EPSS 0.22%
- Veröffentlicht 18.09.2026 07:55:05
- Zuletzt bearbeitet 08.10.2026 20:32:45
HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unautho...
CVE-2026-67102
- EPSS 0.27%
- Veröffentlicht 18.09.2026 07:54:03
- Zuletzt bearbeitet 08.10.2026 20:33:31
HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged roles.