Impact
The vulnerability arises from an improperly validated Origin header that allows an attacker to craft a malicious web page capable of sending requests to the vulnerable HCL BigFix Service Management instance on the victim's behalf. The misuse of CORS controls can result in unauthorized reading of or manipulation of protected data and restricted API endpoints, potentially leading to data disclosure, policy violation, or unauthorized configuration changes.
Affected Systems
The affected product is HCL BigFix Service Management from HCL Software. Version information is not provided, so any installation of the product remains potentially at risk until a patch or configuration change is applied. The vulnerability is specific to the cross‑origin behavior of the web interface, making all network‑exposed instances susceptible.
Risk and Exploitability
The CVSS score of 3.1 indicates low overall severity, and an EPSS score of less than 1% signals a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. An attacker would need to lure a user into visiting a malicious page that issues HTTP requests to the BigFix service; the attack therefore relies on social engineering or compromised content to be served to an authenticated browser session. Because the flaw is limited to improper origin validation, there is no immediate code execution or privilege escalation beyond the browser's context.
OpenCVE Enrichment