Impact
HCL BigFix Service Management is vulnerable to a security misconfiguration that allows an authenticated attacker to access and view restricted data elements across tenant boundaries. The flaw is an improper implementation of access controls (CWE-284), resulting in unauthorized data exposure.
Affected Systems
The affected product is HCL BigFix Service Management from HCL Software. No specific version information is provided in the CVE data, so all installations of the product should be checked against the vendor advisory.
Risk and Exploitability
The CVSS score of 5.0 classifies the vulnerability as moderate severity. The EPSS score of less than 1% suggests a low probability that this flaw is actively exploited. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attacker must be authenticated and that proper access controls are missing, enabling data leakage across tenant boundaries.
OpenCVE Enrichment