Impact
HCL BigFix Service Management contains an information‑disclosure flaw that returns sensitive data in error messages when clients send malformed or unexpected input to specific API endpoints. The exposed data can be leveraged by an attacker to inform subsequent attacks. The weakness corresponds to CWE‑200 (Information Exposure) and CWE‑209 (Information Exposure Through Error Message).
Affected Systems
This vulnerability affects the HCL Software HCL BigFix Service Management product. The advisory does not list particular product versions, so all deployed instances of this application are considered potentially vulnerable until an update is applied.
Risk and Exploitability
The CVSS base score is 3.7, indicating a low severity. The EPSS score is unavailable and the issue is not in the CISA KEV catalog. Attackers would need network access to the API endpoint, and the flaw only exposes information rather than executing code, so the immediate danger is limited. Nevertheless, the disclosed data could give an adversary an advantage to carry out targeted follow‑up attacks or reconnaissance.
OpenCVE Enrichment