product of hcltech

bigfix service management

20 thingsrelated by NVD

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive…
CVE-2026-67106
Severity medium
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network…
CVE-2026-67105
Severity high
HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to…
CVE-2026-67104
Severity medium
HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to…
CVE-2026-56599
Severity low
HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and…
CVE-2026-56589
Severity high
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI…
CVE-2025-52613
Severity high
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header…
CVE-2025-31984
Severity medium
HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers…
CVE-2025-31983
Severity medium
HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could…
CVE-2025-31982
Severity medium
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted…
CVE-2025-31981
Severity medium
HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or…
CVE-2025-31978
Severity medium
HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could…
CVE-2025-31977
Severity medium
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a…
CVE-2025-31976
Severity high
HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners…
CVE-2025-31975
Severity medium
HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system…
CVE-2025-31974
Severity high
HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which…
CVE-2025-31972
Severity medium
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was…
CVE-2025-31960
Severity medium
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and…
CVE-2025-31959
Severity low
HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route…
CVE-2025-31958
Severity high
HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized…
CVE-2025-31957
Severity medium