HCL BigFix Service Management是印度HCL公司的一款IT服务管理与资产运营平台。 HCL BigFix Service Management存在日志信息泄露漏洞,该漏洞源于访问控制失效,可能导致权限提升,允许未经授权的用户获得更高权限,绕过预期访问限制,可能导致敏感数据暴露或未经授权的系统修改。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCL | BigFix Service Management (SM) | 23 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL | BigFix Service Management (SM) | 23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-31951 | 8.8 HIGH | HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggl |
| CVE-2025-31970 | 5.3 MEDIUM | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability |
| CVE-2025-31960 | 5.3 MEDIUM | HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper e |
| CVE-2025-52613 | 4.6 MEDIUM | HCL BigFix Service Management (SM) is affected by use of a vulnerable component |
| CVE-2025-59851 | 3.7 LOW | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability |
| CVE-2025-59852 | 3.7 LOW | HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability |
| CVE-2025-31983 | 3.7 LOW | HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerabilit |
| CVE-2025-31984 | 3.7 LOW | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a mis |
| CVE-2025-59853 | 3.1 LOW | HCL DFXAnalytics is affected by an Improper Error Handling vulnerability |
| CVE-2025-59854 | 3.1 LOW | HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability |
| CVE-2025-62345 | 2.7 LOW | HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” V |
| CVE-2025-31975 | 2.6 LOW | HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banne |
No comments yet