HCL BigFix Service Management是印度HCL公司的一款IT服务管理与资产运营平台。 HCL BigFix Service Management (SM)存在安全漏洞,该漏洞源于报告模块中错误处理不当,在报告查看请求中向consumer_company参数提供无效或超出范围的值时,应用程序触发未处理的异常,可能导致信息暴露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCL | BigFix Service Management (SM) | 23 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL | BigFix Service Management (SM) | 23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-31951 | 8.8 HIGH | HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggl |
| CVE-2024-30151 | 8.3 HIGH | HCL BigFix Service Management (SM) is susceptible to Broken Access Control Vulnerability |
| CVE-2025-31970 | 5.3 MEDIUM | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability |
| CVE-2025-52613 | 4.6 MEDIUM | HCL BigFix Service Management (SM) is affected by use of a vulnerable component |
| CVE-2025-59851 | 3.7 LOW | HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability |
| CVE-2025-59852 | 3.7 LOW | HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability |
| CVE-2025-31983 | 3.7 LOW | HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerabilit |
| CVE-2025-31984 | 3.7 LOW | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a mis |
| CVE-2025-59853 | 3.1 LOW | HCL DFXAnalytics is affected by an Improper Error Handling vulnerability |
| CVE-2025-59854 | 3.1 LOW | HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability |
| CVE-2025-62345 | 2.7 LOW | HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” V |
| CVE-2025-31975 | 2.6 LOW | HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banne |
No comments yet