Impact
HCL BigFix Service Management contains an information disclosure vulnerability: an exposed API endpoint leaks sensitive internal database details. An attacker who can reach this endpoint could obtain data that supports targeted database attacks, compromising confidentiality of the system. The weakness is identified as CWE‑200 and CWE‑209 and requires remote access to the service to be exploited.
Affected Systems
The affected product is HCL Software's HCL BigFix Service Management. Specific product versions are not listed in the CNA data, so all released versions may be vulnerable until patched.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level. With no EPSS value provided, the probability of exploitation remains unclear, but the vulnerability is not catalogued in CISA's KEV list. The most likely attack vector is remote, via the exposed API endpoint, and would need only network access to the BigFix Service Management instance. No specific exploitation conditions or dependencies are noted in the description.
OpenCVE Enrichment