HCL BigFix Service Management 存在管理会话并发漏洞。该应用程序允许同一管理员账户同时存在多个已认证会话,这使得未经授权的攻击者能够预测或劫持有效的会话标识符。若成功利用此漏洞,攻击者可接管受影响的管理员会话,并以完全特权用户的权限执行操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCL Software | HCL BigFix Service Management | Version 27 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL Software | HCL BigFix Service Management | Version 27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67100 | 9.8 CRITICAL | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-67101 | 9.3 CRITICAL | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-67102 | 8.1 HIGH | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-67103 | 7.6 HIGH | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-56592 | 6.5 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-56590 | 6.4 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-21822 | 6.3 MEDIUM | A path traversal vulnerability has been identified in HCL AppScan 360° (CVE-2026-21822). |
| CVE-2026-21848 | 5.0 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-56597 | 3.1 LOW | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-56595 | 3.1 LOW | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
No comments yet