Impact
HCL BigFix Mobile suffers from improper handling of exceptions and verbose error reporting, causing the application to reveal sensitive information. Exploiting this flaw allows an adversary to view data that should remain confidential, such as system details or operational credentials, as defined by CWE-209. The disclosed data compromises confidentiality and may aid further attacks, but it does not directly alter system integrity or availability.
Affected Systems
The vulnerability is present in HCL Software’s HCL BigFix Mobile product. No specific affected version information is provided in the CNA data, so all releases of this application are potentially impacted unless a later patch explicitly excludes them.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑moderate risk level. No EPSS score is available, and the flaw is not listed in the CISA known‑exploited vulnerabilities catalog. The attack vector is not explicitly stated, but as the flaw arises from unhandled exceptions, it is inferred that an attacker could trigger it by interacting with the application (either locally or remotely) and observing the resulting verbose error output.
OpenCVE Enrichment