HCL BigFix Quantum Risk Analyzer 默认生成高度详细的日志信息,这增加了敏感数据泄露的风险,并可能向攻击者暴露内部应用逻辑和架构细节。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCLSoftware | BigFix Quantum Risk Analyzer | 2.0.1.47 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-21810 | 4.4 MEDIUM | HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference an |
| CVE-2026-21809 | 3.9 LOW | HCL BigFix Quantum Risk Analyzer is affected by generating error messages with sensitive i |
| CVE-2026-21807 | 3.9 LOW | HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflow |
| CVE-2025-62341 | 3.7 LOW | HCL Connections is vulnerable to server-side request forgery (SSRF) |
| CVE-2026-56547 | 3.5 LOW | An input reflection vulnerability affects HCL Traveler |
No comments yet