Impact
The vulnerability allows an unauthenticated attacker to download publicly visible JavaScript files and analyze their code, which reveals hidden administrative API endpoints. This information disclosure can be leveraged for further, targeted attacks against the system. The weakness is categorized under CWE-200 and CWE-798, indicating a lack of appropriate access controls and potential exposure of privileged data.
Affected Systems
The affected product is HCL BigFix Service Management from HCL Software. No specific product versions are listed in the current data.
Risk and Exploitability
With a CVSS score of 5.3, the severity is moderate. EPSS information is unavailable, and the vulnerability is not listed in CISA KEV catalog. The attack vector is inferred to be a remote, unauthenticated network request to retrieve JavaScript files, a path that is typically exposed over HTTP/HTTPS. The potential for exploitation exists only if the exposed administrative APIs are subsequently accessed without additional safeguards.
OpenCVE Enrichment