HCL BigFix Service Management 存在信息泄露漏洞,原因是两个已暴露的 API 端点返回了敏感数据。这些信息可能被攻击者利用,以发起更严重、更具破坏性的后续攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL Software | HCL BigFix Service Management | Version 27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66246 | 8.8 HIGH | HCL iControl is affected by multiple security vulnerabilities |
| CVE-2026-67105 | 7.4 HIGH | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-56589 | 7.2 HIGH | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-67171 | 5.3 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-67104 | 5.3 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2025-31980 | 4.3 MEDIUM | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-66247 | 4.3 MEDIUM | iControl不安全CORS策略致敏感数据泄露漏洞 |
| CVE-2026-21833 | 3.7 LOW | HCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnerability (CVE-2 |
| CVE-2026-67172 | 3.7 LOW | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-66253 | 3.1 LOW | HCL iControl is affected by a Session Timeout vulnerability |
| CVE-2026-66249 | 3.1 LOW | HCL iControl is affected by a Missing Secure Attribute vulnerability |
| CVE-2026-66248 | 3.1 LOW | HCL iControl is affected by an Improper Error Handling vulnerability |
| CVE-2026-56599 | 2.2 LOW | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
No comments yet