Impact
The vulnerability lies in the default logging configuration of HCL BigFix Quantum Risk Analyzer, which records highly detailed activity. This excessive detail can expose sensitive data and internal application logic to anyone with access to the logs, thereby compromising confidentiality and potentially aiding attackers in understanding the system architecture.
Affected Systems
The affected product is HCL Software’s BigFix Quantum Risk Analyzer. No specific version range is listed in the available data.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity. The exploit probability is not quantified (EPSS not available), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers would require access to the system’s log files, which may be achievable by a privileged user or a compromised local account. Once accessed, the logs could provide actionable insights into the application’s internal structure.
OpenCVE Enrichment