Sensitive Information Leakage in HCL BigFix Service Management
CVE-2026-56597

3.1LOW

What is CVE-2026-56597?

HCL BigFix Service Management is susceptible to a Sensitive Information Leakage vulnerability, allowing unauthorized attackers to extract sensitive internal IP address information from the application responses. This could enable attackers to create a detailed map of the network topology, subsequently identifying vulnerable internal systems and potential attack vectors. Ensuring proper access controls and monitoring responses can mitigate the risks associated with this vulnerability.

Affected Version(s)

HCL BigFix Service Management v27

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.