Impact
The vulnerability is an Improper Input Validation flaw that allows an attacker to submit malformed or unexpected data. This can cause processing errors, bias the business logic, and trigger unintended behavior or denial of service. The CVSS score of 3.5 indicates a low severity but the impact could compromise system stability or unintentional configuration changes.
Affected Systems
The affected product is HCL BigFix Service Management from HCL Software. No specific version information is available, so all current and older releases could be impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 3.5 reflects a low overall risk, but the lack of an EPSS score means that exploitation likelihood is unknown. KEV does not list this vulnerability. Based on the description, it is inferred that the flaw could be triggered by external input—such as form submissions or API calls—without proper validation, allowing an attacker to supply special characters or payloads that the system misprocesses.
OpenCVE Enrichment