Impact
HCL BigFix Service Management contains a SQL Injection flaw and a cross-tenant data exposure flaw that can be exploited by an authenticated attacker. By injecting malicious SQL statements, an attacker may read sensitive system information from the database, while manipulating request values can allow unauthorized access to full personal profile data and personally identifiable information from other organizations. The primary impact is the potential exfiltration of confidential data, which compromises confidentiality and could serve as an initial foothold for further attacks. The likely attack vector is an authenticated session to the web interface, where input parameters are not properly validated or sanitized, enabling exploitation without additional privileges.
Affected Systems
HCL Software’s HCL BigFix Service Management is the vendor and product affected by this vulnerability. No specific release or patch levels are listed in the advisory; all deployments of the product should be assessed for the presence of these flaws and updated accordingly.
Risk and Exploitability
The vulnerability’s CVSS score of 9.8 indicates critical severity, and the EPSS score of less than 1% suggests attackers are not actively exploiting it yet, but its presence in a production environment poses a high risk due to the ease of exploitation for authenticated users. The issue is not currently listed in CISA’s Known Exploited Vulnerabilities catalog, yet the combination of data exposure and injection could enable further compromise if an attacker gains temporary access to a valid account. Mitigating this risk requires applying the vendor’s patch and enforcing strict access controls.
OpenCVE Enrichment