VulnSea

hcl_bigfix_service_management vulnerabilities

CVEs whose affected-version data names the hcl_bigfix_service_management package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

CVE-2026-21806Low· 3.1
3d ago

HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability

HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.15%via NVD
CVE-2026-21848Medium· 5.0
3d ago

HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across…

HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.20%via NVD
CVE-2026-56590Medium· 6.4
3d ago

HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a compl…

HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a compl…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.17%via NVD
CVE-2026-56597Low· 3.1
3d ago

HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underly…

HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underly…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.16%via NVD
CVE-2026-56595Low· 3.1
3d ago

HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, en…

HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, en…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.15%via NVD
CVE-2026-56592Medium· 6.5
3d ago

HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the l…

HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the l…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.25%via NVD
CVE-2026-67103High· 7.6
3d ago

HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover…

HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover…

TwilightHCL Software · HCL BigFix Service ManagementEPSS 0.22%via NVD
CVE-2026-67102High· 8.1
3d ago

HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged …

HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged …

TwilightHCL Software · HCL BigFix Service ManagementEPSS 0.27%via NVD
CVE-2026-67101Critical· 9.3
3d ago

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not …

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not …

MidnightHCL Software · HCL BigFix Service ManagementEPSS 0.27%via NVD
CVE-2026-67100Critical· 9.8
3d ago

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well a…

MidnightHCL Software · HCL BigFix Service ManagementEPSS 0.35%via NVD
hcl_bigfix_service_management vulnerabilities (CVEs) · VulnSea