HCL Software HCL BigFix Service Management

18 known vulnerabilities in HCL Software HCL BigFix Service Management, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-67172 CVSS 3.7 low HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in…
  • CVE-2026-67171 CVSS 5.3 medium HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive…
  • CVE-2025-31980 CVSS 4.3 medium HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject…
  • CVE-2026-67106 CVSS 5.3 medium HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive…
  • CVE-2026-67105 CVSS 7.4 high HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network…
  • CVE-2026-67104 CVSS 5.3 medium HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to…
  • CVE-2026-56599 CVSS 2.2 low HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to…
  • CVE-2026-56589 CVSS 7.2 high HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject…
  • CVE-2026-21806 CVSS 3.1 low HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple…
  • CVE-2026-56597 CVSS 3.1 low HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker…
  • CVE-2026-56595 CVSS 3.1 low HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could…
  • CVE-2026-56592 CVSS 6.5 medium HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts…
  • CVE-2026-56590 CVSS 6.4 medium HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which…
  • CVE-2026-21848 CVSS 5.0 medium HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to…
  • CVE-2026-67103 CVSS 7.6 high HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized…
  • CVE-2026-67102 CVSS 8.1 high HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user…
  • CVE-2026-67101 CVSS 9.3 critical HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could…
  • CVE-2026-67100 CVSS 9.8 critical HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow…