Description
HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks.
Published: 2026-10-01
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

HCL BigFix Service Management contains an information‑disclosure flaw that returns sensitive data in error messages when clients send malformed or unexpected input to specific API endpoints. The exposed data can be leveraged by an attacker to inform subsequent attacks. The weakness corresponds to CWE‑200 (Information Exposure) and CWE‑209 (Information Exposure Through Error Message).

Affected Systems

This vulnerability affects the HCL Software HCL BigFix Service Management product. The advisory does not list particular product versions, so all deployed instances of this application are considered potentially vulnerable until an update is applied.

Risk and Exploitability

The CVSS base score is 3.7, indicating a low severity. The EPSS score is unavailable and the issue is not in the CISA KEV catalog. Attackers would need network access to the API endpoint, and the flaw only exposes information rather than executing code, so the immediate danger is limited. Nevertheless, the disclosed data could give an adversary an advantage to carry out targeted follow‑up attacks or reconnaissance.

Generated by OpenCVE AI on October 1, 2026 at 17:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade HCL BigFix Service Management to the newest release that addresses the issue.
  • Configure the application or web server to suppress detailed error messages from the affected API endpoints in a production environment.
  • Restrict network access to the API endpoints to trusted hosts or networks using firewall or segmentation rules.
  • Monitor API traffic for anomalous error responses that may indicate attempts to exploit the disclosure flaw.

Generated by OpenCVE AI on October 1, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks.
Title HCL BigFix Service Management is affected by multiple security vulnerabilities.
Weaknesses CWE-200
CWE-209
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-10-01T16:32:29.656Z

Reserved: 2026-07-28T13:24:27.384Z

Link: CVE-2026-67172

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T17:17:30.290

Modified: 2026-10-01T20:36:15.187

Link: CVE-2026-67172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:00:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-209

    Generation of Error Message Containing Sensitive Information