HCL BigFix RunBookAI是印度HCL公司的一个人工智能自动化产品。 HCL BigFix RunBookAI存在命令注入漏洞,该漏洞源于未验证的命令输入或潜在的命令夹带,组件输入处理存在缺陷,可能允许未经授权的命令执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCL | BigFix RunBookAI | 11.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL | BigFix RunBookAI | 11.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-30151 | 8.3 HIGH | HCL BigFix Service Management (SM) is susceptible to Broken Access Control Vulnerability |
| CVE-2025-31970 | 5.3 MEDIUM | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability |
| CVE-2025-31960 | 5.3 MEDIUM | HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper e |
| CVE-2025-52613 | 4.6 MEDIUM | HCL BigFix Service Management (SM) is affected by use of a vulnerable component |
| CVE-2025-59851 | 3.7 LOW | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability |
| CVE-2025-59852 | 3.7 LOW | HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability |
| CVE-2025-31983 | 3.7 LOW | HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerabilit |
| CVE-2025-31984 | 3.7 LOW | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a mis |
| CVE-2025-59853 | 3.1 LOW | HCL DFXAnalytics is affected by an Improper Error Handling vulnerability |
| CVE-2025-59854 | 3.1 LOW | HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability |
| CVE-2025-62345 | 2.7 LOW | HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” V |
| CVE-2025-31975 | 2.6 LOW | HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banne |
No comments yet