Description
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

HCL BigFix Service Management contains an information disclosure vulnerability: an exposed API endpoint leaks sensitive internal database details. An attacker who can reach this endpoint could obtain data that supports targeted database attacks, compromising confidentiality of the system. The weakness is identified as CWE‑200 and CWE‑209 and requires remote access to the service to be exploited.

Affected Systems

The affected product is HCL Software's HCL BigFix Service Management. Specific product versions are not listed in the CNA data, so all released versions may be vulnerable until patched.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk level. With no EPSS value provided, the probability of exploitation remains unclear, but the vulnerability is not catalogued in CISA's KEV list. The most likely attack vector is remote, via the exposed API endpoint, and would need only network access to the BigFix Service Management instance. No specific exploitation conditions or dependencies are noted in the description.

Generated by OpenCVE AI on October 1, 2026 at 17:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch or fix provided by HCL Software – view the HCL support article KB0134015 for update details.
  • Restrict network access to the exposed API endpoint using firewalls or network segmentation, allowing only trusted hosts to reach it.
  • Configure or enforce authentication and authorization on the API to limit which users or services can retrieve database information.

Generated by OpenCVE AI on October 1, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech bigfix Service Management
Vendors & Products Hcltech
Hcltech bigfix Service Management

Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks.
Title HCL BigFix Service Management is affected by multiple security vulnerabilities.
Weaknesses CWE-200
CWE-209
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hcltech Bigfix Service Management
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-10-01T16:32:08.151Z

Reserved: 2026-07-28T13:24:27.384Z

Link: CVE-2026-67171

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T17:17:30.157

Modified: 2026-10-01T20:36:15.187

Link: CVE-2026-67171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:15:11Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-209

    Generation of Error Message Containing Sensitive Information