Information Disclosure Vulnerability in HCL BigFix Service Management
CVE-2026-67172

3.7LOW

What is CVE-2026-67172?

HCL BigFix Service Management is vulnerable to an information disclosure issue that occurs when invalid inputs are processed by specific API endpoints. In such instances, the application inadvertently returns sensitive information within error messages. This exposed data could potentially be leveraged by attackers to launch further attacks against the system, making it essential for users to remediate this vulnerability promptly.

Affected Version(s)

HCL BigFix Service Management Version 27

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.