Impact
The vulnerability is a Server‑Side Request Forgery in the search functionality of HCL BigFix Service Management. By sending crafted search queries, an attacker can cause the application server to generate HTTP requests to arbitrary internal addresses that are normally unreachable from the public network. This enables the attacker to probe or access internal services, exfiltrate sensitive data, or pivot to other components, potentially compromising confidentiality and integrity of internal resources.
Affected Systems
HCL BigFix Service Management, developed by HCL Software. No specific affected version data is provided in the advisory, so all installations may be at risk pending vendor confirmation.
Risk and Exploitability
The CVSS score of 9.3 indicates high severity, while the EPSS score of <1% suggests a low current likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. Attackers would likely exploit the SSRF by writing malicious search parameters into the BigFix web interface; successful exploitation requires access to the internal application network and the ability to send requests from the server. Because the vulnerability allows arbitrary outbound requests, a compromised server could be used to move laterally or exfiltrate data.
OpenCVE Enrichment