HCL BigFix Quantum Risk Analyzer 受硬编码的外部资源引用和二进制文件完整性缺失的影响,攻击者借此可能获取敏感信息或篡改二进制文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCLSoftware | BigFix Quantum Risk Analyzer | 2.0.1.47 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-21808 | 4.1 MEDIUM | HCL BigFix Quantum Risk Analyzer is affected by logging sensitive information |
| CVE-2026-21809 | 3.9 LOW | HCL BigFix Quantum Risk Analyzer is affected by generating error messages with sensitive i |
| CVE-2026-21807 | 3.9 LOW | HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflow |
| CVE-2025-62341 | 3.7 LOW | HCL Connections is vulnerable to server-side request forgery (SSRF) |
| CVE-2026-56547 | 3.5 LOW | An input reflection vulnerability affects HCL Traveler |
No comments yet